These are the latest updates we've made to our platform. If you have any questions about any of the updates you see below, please feel free to contact us!
SonicWall’s Secure Mobile Access 1000 Series has a newly disclosed RCE —CVE-2025-23006 (CVSSv3 9.8) that allows an unauthenticated attacker to run arbitrary code on the target.
Sniper: Auto-Exploiter now supports three high-risk CVEs, helping you validate exploitability with just a few clicks — no manual scripting needed:
✅ CVE-2024-11635 (CVSSv3 9.8) – an RCE in WordPress File Upload plugin using the require-once PHP statement, with attacker controllable data as an argument.
✅ CVE-2025-0890 (CVSSv3 9.8) – insecure default credentials for the Telnet function in Zyxel devices allowing an attacker to fully compromise your server.
✅ CVE-2024-40891 (CVSSv3 8.8) – a post-authentication command injection vulnerability in Zyxel via Telnet.
For consultants, this means stronger deliverables and faster turnaround. For internal teams, actionable exploitability validation without time-consuming setup.
Bonus reminder: all these CVEs can be detected with our Network Scanner.
March 2025
Detect CVE-2025-29927, the vulnerability in Next.js middleware, fast and effectively
Our Network Scanner now provides fast, reliable detection for the critical Next.js vulnerability, CVE-2025-29927, so you can quickly identify affected applications.
We've streamlined the detection process to help you pinpoint and address this risk effectively.
How it works:
✅ Run a CVE-focused network vulnerability scan against your Next.js applications.
✅ The scanner will automatically check for CVE-2025-29927, highlighting vulnerable instances.
✅ Get clear, actionable results to prioritize patching and mitigation.
Dive deeper: understand and fix CVE-2025-29927
For a comprehensive understanding of the CVE-2025-29927 vulnerability, its impact, and detailed remediation steps, read our in-depth article.
This write-up includes:
A technical breakdown of the vulnerability.
Affected Next.js versions.
Practical exploitation scenarios.
Business impact examples.
Step-by-step mitigation guidance.
Catch email leaks, DOM-based redirects & XSS with ease
This month’s Website Scanner updates help you uncover hard-to-spot web app issues faster:
📌 Redirects buried in JavaScript can slip past traditional scans. Now our scanner checks for DOM-based open redirects, giving you deeper visibility into vulnerable behavior inside the browser.
📌 See emails as standalone findings for faster review and better reporting.
📌 Found an XSS? No need to manually recreate your payload - just click “Exploit with XSS Exploiter” in the Website Scanner and capture screenshots, cookies, and request data every time it gets triggered.
Edit scheduled scan notifications without starting over
Misconfigured buckets can leak versioned objects, exposing sensitive data. Our Cloud Scannerhas a new finding for publicAWS S3 bucket version listings, so you can:
✅ Spot dangerous misconfigs fast and remediate ✅ Support continuous secure cloud hygiene
Our pentest robots are becoming increasingly popular for handling large-scale vulnerability assessments. And now, they're even easier to use, especially for those of you who need customized automation.
We’ve made it simpler to keep track of pentest robots scans: instead of listing all scans individually, the Scans section now displays one entry per pentest robot, making it easier to map your actions to what you see in our product.
How it works:
✅ Each pentest robot now has a single log entry, reducing clutter
✅ You can access all scan resulting from a single pentest robot accessed within its own log block
✅ Improved clarity helps you focus on results - not on tracking individual scans.
Need to prove exploitability for highly targeted CVEs beyond a shadow of a doubt?
Our proprietary offensive tool, Sniper: Auto-Exploiter, is now even more powerful, helping you get proof of exploitation for critical vulnerabilities in popular content management systems:
CVE-2024-10924 (CVSSv3 9.8) - an RCE in the Really Simple Security WordPress plugin that can let an attacker leverage an authentication bypass and compromise your server.
CVE-2023-41892 (CVSSv3 9.8) - a Craft CMS Unauthenticated RCE classified as a high-impact, low-complexity attack vector.
And remember: if it’s exploitable with Sniper, it’s a confirmed risk you can also detect with our Network Vulnerability Scanner.
Brute-force battle: we tested Hydra vs our Password Auditor against 26 web apps!
We ran Hydra, a pentester’s favourite, and our proprietary Password Auditor against 26 web applications— including Microsoft Exchange, WordPress, and Joomla.
The comparison criteria? Their ability to:
Identify login credentials, endpoints and parameters
Recognize error messages & protection mechanisms
Detect defensive measures like IP blacklisting, CAPTCHA, account lockout, and rate limiting.
The results make choosing a tool for password auditing much easier: Hydra might be a classic, but our Password Auditor is the real match for modern security defenses.
Also included in this benchmark: a step-by-step guide to bruteforcing all 26 tested apps, from WordPress to Exchange.
Analyze findings faster with even more refreshed results
To help you get eyes on the most burning security issues as fast as possible, we’ve updated the Website Scanner and the API Scanner to classify the most severe risks as Critical if their CVSSv3 score is over 9.0.
This means:
📌 More time to realistically assess business impact
📌 More accurate risk and mitigation prioritization.
Plus, this month comes with even more improvements in our Website Scanner:
You can now test authentication with headers with the Authentication functionality, before starting a new scan for a better setup configuration.
The Find Login Interfaces passive test now detects Basic HTTP/NTLM Authentication — helping you map authentication entry points with greater accuracy.
January 2025
Reduce your attack surface faster with critical network findings
That’s why it now generates critical findings if the CVSSv3 score is over 9.0, to help you prioritize and address the most urgent vulnerabilities more efficiently.
People Hunter lets you discover email addresses and social media profiles starting from a web application — for a more accurate attack surface assessment.
Now it’s faster with these two key optimizations:
Get results in real-time as the crawler works its ways through the target
Besides finding critical vulnerabilities in web apps, our proprietary Website Scanner automatically validates them to get rid of false positives.
In the last few weeks, we’ve added even more highly accurate detections for:
insecure deserialization in Ruby-based applications with the scanner’s Active module.
Python pickle objects, together with an out of band deserialization method so you don’t get any unwanted RCEs in production.
Wondering what else you can detect with our Website Scanner? Find all our web app detections in the Vulnerability Database by filtering after the tool’s name!
We’ve made one of the top 3 Pentest-Tools.com favorites even faster! 50% faster for deep scans!
Without compromising on quality, our Subdomain Finder gets results much quicker thanks to this latest improvement: loading fingerprinting tools in a more efficient way.