[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"all-banners":3,"SkipToContent_34xgpJIRRkpiT6ls6jE4NHf7VpvQCQBEwi69exi4oT0":44,"FormattedDate_gSPz6jjKmpkglb7usKJymmXvmOFR18CTEKmpWuBWTKw":51,"FooterNav_JsYsxvLufb1W12aeknKZ89on0MD0bNDTiB5EYxyxmU":58,"FooterSocial_u16tCafBUeGMoDrdLfTINytP2JB5msc6iB3VDUutAoU":64,"$f2r4b9phgo6bha":71,"$f17q7jdn7tll3p":73,"finding-templates-{\"q\":\"\",\"page\":1}":106},[4,15,21,27,33,39],{"title":5,"slug":6,"text":7,"link":8,"external":9,"targets":10,"cta":12,"variant":13,"campaign_id":14},"Compliance - Page Launch - Network Scanner","compliance-pages-launch-network-scanner","Scheduled scans are the spine of every compliance framework. Are you audit-ready?","https:\u002F\u002Fpentest-tools.com\u002Fusage\u002Fcompliance",false,[11],"\u002Fnetwork-vulnerability-scanning\u002Fnetwork-security-scanner-online","Get compliance evidence","secondary","compliance-pages-launch",{"title":16,"slug":17,"text":18,"link":8,"external":9,"targets":19,"cta":12,"variant":13,"campaign_id":14},"Compliance - Page Launch - Website Scanner","compliance-pages-launch-website-scanner","Authenticated web-app scans show up in SOC 2, NIS2, and CRA Annex I. See why this is crucial for the business.",[20],"\u002Fwebsite-vulnerability-scanning\u002Fwebsite-scanner",{"title":22,"slug":23,"text":24,"link":8,"external":9,"targets":25,"cta":12,"variant":13,"campaign_id":14},"Compliance - Page Launch - Advanced Pentest Reporting","compliance-pages-launch-reporting","Editable DOCX. Immutable PDF. JSON for the GRC tool. See why these formats are on every auditor's checklist.",[26],"\u002Ffeatures\u002Fpentest-reporting",{"title":28,"slug":29,"text":30,"link":8,"external":9,"targets":31,"cta":12,"variant":13,"campaign_id":14},"Compliance - Page Launch - Integrations","compliance-pages-launch-integrations","Vanta, Jira, webhooks - they all route back to DORA, NIS2, SOC 2, ISO 27001, CRA. See why this is crucial for the business.",[32],"\u002Ffeatures\u002Fintegrations",{"title":34,"slug":35,"text":36,"link":8,"external":9,"targets":37,"cta":12,"variant":13,"campaign_id":14},"Compliance - Page Launch - Sniper","compliance-pages-launch-sniper","Five compliance framework pages now reference Sniper as the source of validated exploitability evidence. See them all.",[38],"\u002Fexploit-helpers\u002Fsniper",{"title":40,"slug":14,"text":41,"link":8,"external":9,"targets":42,"cta":12,"variant":13,"campaign_id":14},"Compliance - Page Launch - Homepage","Turn confirmed vulnerabilities into evidence your auditor accepts. Testing requirements for DORA, NIS2, SOC 2, ISO 27001, and CRA.",[43],"\u002F",["Island",45],{"key":46,"params":47,"result":49},"SkipToContent_34xgpJIRRkpiT6ls6jE4NHf7VpvQCQBEwi69exi4oT0",{"props":48},"{}",{"head":50},{},["Island",52],{"key":53,"params":54,"result":56},"FormattedDate_gSPz6jjKmpkglb7usKJymmXvmOFR18CTEKmpWuBWTKw",{"props":55},"{\"date\":1790164173,\"format\":\"MMMM dd, yyyy\"}",{"head":57},{},["Island",59],{"key":60,"params":61,"result":62},"FooterNav_JsYsxvLufb1W12aeknKZ89on0MD0bNDTiB5EYxyxmU",{"props":48},{"head":63},{},["Island",65],{"key":66,"params":67,"result":69},"FooterSocial_u16tCafBUeGMoDrdLfTINytP2JB5msc6iB3VDUutAoU",{"props":68},"{\"text-color\":\"gray\"}",{"head":70},{},{"count":72},210,{"count":74,"next":75,"previous":76,"results":77},17461,"https:\u002F\u002Fvulndb.pentest-tools.com\u002Fapi\u002Fvulns\u002F?page=2&page_size=1",null,[78],{"id":79,"detectable_with":80,"vuln_details":87,"vuln_id":103,"name":104,"published":105,"updated":76},29777,{"tool":81,"engine":84},{"id":82,"name":83},1,"Network Scanner",{"id":85,"name":86},2,"Nuclei",{"id":79,"epss_score":88,"epss_percentile":89,"in_cisa_catalog":9,"codename":76,"public_description":90,"description":76,"severity":91,"risk_description":76,"public_recommendation":92,"recommendation":76,"references":93,"cvssv3":97,"cve":98,"date":100,"software_type":76,"vendor":101,"product":102,"ptt_exploit_capabilities":76,"category":76},0.03033,0.87045,"LiteLLM Proxy before 1.84.0 derives its public-route authorization check from a URL reconstructed with the unvalidated Host header. A Host value containing a fragment can make a protected request appear to target the public root route, bypassing the API-key check. Version 1.84.0 derives the route from the raw ASGI path instead.","high","Upgrade LiteLLM Proxy to 1.84.0 or later.",[94,95,96],"https:\u002F\u002Fgithub.com\u002FBerriAI\u002Flitellm\u002Fsecurity\u002Fadvisories\u002FGHSA-4xpc-pv4p-pm3w","https:\u002F\u002Fgithub.com\u002FBerriAI\u002Flitellm\u002Freleases\u002Ftag\u002Fv1.84.0","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-49468",8.1,[99],"CVE-2026-49468","2026-06-22T00:00:00Z","berriai","litellm","NETSCAN-NUCLEI-CVE-CVE-2026-49468","LiteLLM Proxy \u003C 1.84.0 - Host Header Authentication Bypass (CVE-2026-49468)","2026-10-02T00:00:00Z",{"count":74,"next":107,"previous":76,"results":108},"https:\u002F\u002Fvulndb.pentest-tools.com\u002Fapi\u002Fvulns\u002F?limit=25&page=2&search=",[109,117,149,173,197,222,249,276,302,324,351,375,398,425,447,469,490,512,533,556,583,599,622,644,660],{"id":79,"detectable_with":110,"vuln_details":113,"vuln_id":103,"name":116,"published":105,"updated":76},{"tool":111,"engine":112},{"id":82,"name":83},{"id":85,"name":86},{"id":79,"codename":76,"description":76,"severity":91,"risk_description":76,"public_description":90,"public_recommendation":92,"recommendation":76,"references":114,"cvssv3":97,"epss_score":88,"epss_percentile":89,"cve":115,"in_cisa_catalog":9,"date":100,"software_type":76,"vendor":101,"product":102,"ptt_exploit_capabilities":76},[94,95,96],[99],"LiteLLM Proxy \u003C 1.84.0 - Host Header Authentication Bypass",{"id":118,"detectable_with":119,"vuln_details":123,"vuln_id":146,"name":147,"published":148,"updated":148},29785,{"tool":120,"engine":121},{"id":82,"name":83},{"id":82,"name":122},"Sniper",{"id":118,"codename":76,"description":124,"severity":125,"risk_description":126,"public_description":127,"public_recommendation":128,"recommendation":129,"references":130,"cvssv3":134,"epss_score":135,"epss_percentile":136,"cve":137,"in_cisa_catalog":139,"date":140,"software_type":141,"vendor":142,"product":143,"ptt_exploit_capabilities":144},"We found that the target server is vulnerable to CVE-2026-88771, a Remote Code Execution vulnerability affecting Citrix NetScaler ADC and NetScaler Gateway. The root cause is an OS command injection in an appliance monitoring script that parses NetScaler crash logs and interpolates an attacker-controlled value, poisoned through the unauthenticated Gateway authentication endpoint, unquoted into a shell command. This allows an unauthenticated remote attacker to execute arbitrary commands as root, in the default configuration. We detected this vulnerability by fingerprinting the NetScaler build and confirming it is older than the patched version.","critical","The risk exists that an unauthenticated remote attacker could gain Remote Code Execution access as root which will result in a fully compromised appliance through which they could steal confidential information, deploy webshells, install ransomware, or pivot to the internal network.","Citrix NetScaler ADC and NetScaler Gateway are vulnerable to CVE-2026-88771, a Remote Code Execution vulnerability. An OS command injection in an appliance monitoring script, reachable through the unauthenticated authentication endpoint, allows an unauthenticated remote attacker to execute arbitrary commands as root in the default configuration.","Update Citrix NetScaler ADC and NetScaler Gateway to a fixed version (14.1-73.37, 13.1-64.23, or later) as described in Citrix bulletin CTX697096.","We recommend to update Citrix NetScaler ADC and NetScaler Gateway to a fixed version (14.1-73.37, 13.1-64.23, or later) as described in Citrix bulletin CTX697096. End-of-life releases (12.1 and 13.0) do not receive a fix and should be migrated to a supported version.",[131,132,133],"https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-88771","https:\u002F\u002Fsupport.citrix.com\u002Farticle\u002FCTX697096","https:\u002F\u002Flabs.watchtowr.com\u002Foh-look-the-foot-gun-went-off-again-citrix-netscaler-preauth-command-injection-cve-2026-88771\u002F",9.5,0.01063,0.63433,[138],"CVE-2026-88771",true,"2026-09-27T00:00:00Z","Network Management","Citrix","Citrix NetScaler",[145],"RCE","NETSCAN-SNIPER-CVE-2026-88771","Citrix NetScaler - Remote Code Execution","2026-09-30T00:00:00Z",{"id":150,"detectable_with":151,"vuln_details":154,"vuln_id":171,"name":172,"published":148,"updated":76},29776,{"tool":152,"engine":153},{"id":82,"name":83},{"id":85,"name":86},{"id":150,"codename":76,"description":76,"severity":125,"risk_description":155,"public_description":156,"public_recommendation":157,"recommendation":76,"references":158,"cvssv3":164,"epss_score":165,"epss_percentile":166,"cve":167,"in_cisa_catalog":9,"date":169,"software_type":76,"vendor":170,"product":170,"ptt_exploit_capabilities":76},"The risk exists that a remote unauthenticated attacker can fully compromise the server to steal confidential information, install ransomware, or pivot to the internal network.","Gotenberg through 8.30.1 sanitizes only the keys of the JSON metadata submitted to the PDF metadata write endpoint, leaving the values unvalidated. A newline inside a metadata value is written straight to the ExifTool process standard input, where it terminates the current argument and starts a new one, letting an unauthenticated attacker inject arbitrary ExifTool arguments and execute operating system commands through an advanced formatting expression.","Update to version 8.31.0 or later, which validates metadata values in addition to metadata keys.",[159,160,161,162,163],"https:\u002F\u002Fgithub.com\u002Fgotenberg\u002Fgotenberg\u002Fsecurity\u002Fadvisories\u002FGHSA-q7r4-hc83-hf2q","https:\u002F\u002Fgithub.com\u002Fgotenberg\u002Fgotenberg\u002Fcommit\u002F405f1069c026bb08f319fb5a44e5c67c33208318","https:\u002F\u002Fgithub.com\u002Fgotenberg\u002Fgotenberg\u002Freleases\u002Ftag\u002Fv8.31.0","https:\u002F\u002Fgithub.com\u002Fvulhub\u002Fvulhub\u002Ftree\u002Fmaster\u002Fgotenberg\u002FCVE-2026-40281","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-40281",9.1,0.02094,0.80978,[168],"CVE-2026-40281","2026-05-06T00:00:00Z","gotenberg","NETSCAN-NUCLEI-CVE-CVE-2026-40281","Gotenberg \u003C= 8.30.1 - Remote Code Execution",{"id":174,"detectable_with":175,"vuln_details":178,"vuln_id":194,"name":195,"published":196,"updated":76},29773,{"tool":176,"engine":177},{"id":82,"name":83},{"id":85,"name":86},{"id":174,"codename":76,"description":76,"severity":179,"risk_description":180,"public_description":181,"public_recommendation":182,"recommendation":76,"references":183,"cvssv3":186,"epss_score":187,"epss_percentile":188,"cve":189,"in_cisa_catalog":9,"date":191,"software_type":76,"vendor":192,"product":193,"ptt_exploit_capabilities":76},"medium","An unauthenticated attacker can enumerate the vessel data schema, connected hardware serial ports, and installed analyzer tooling, aiding reconnaissance for further attacks against the marine data server.","Signal K Server versions up to and including 2.18.0 expose the \u002FskServer\u002Fserialports, \u002FskServer\u002FavailablePaths, and \u002FskServer\u002FhasAnalyzer endpoints without authentication. These routes were missing from the authentication middleware configuration, letting any unauthenticated user retrieve the full Signal K data schema, the list of connected serial devices, and whether traffic analyzer tools are installed. This template fingerprints the server via the public \u002Fsignalk discovery endpoint and flags builds older than the fixed 2.19.0 release.","Upgrade to Signal K Server 2.19.0 or later, which adds the missing endpoints to the authentication middleware.",[184,185],"https:\u002F\u002Fgithub.com\u002FSignalK\u002Fsignalk-server\u002Fsecurity\u002Fadvisories\u002FGHSA-fpf5-w967-rr2m","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2025-68273",5.3,0.00823,0.55807,[190],"CVE-2025-68273","2026-01-01T00:00:00Z","signalk","signalk-server","NETSCAN-NUCLEI-CVE-CVE-2025-68273","Signal K Server \u003C= 2.18.0 - Information Disclosure","2026-09-29T00:00:00Z",{"id":198,"detectable_with":199,"vuln_details":202,"vuln_id":220,"name":221,"published":196,"updated":196},29783,{"tool":200,"engine":201},{"id":82,"name":83},{"id":82,"name":122},{"id":198,"codename":203,"description":204,"severity":125,"risk_description":155,"public_description":205,"public_recommendation":206,"recommendation":207,"references":208,"cvssv3":211,"epss_score":212,"epss_percentile":213,"cve":214,"in_cisa_catalog":9,"date":216,"software_type":217,"vendor":218,"product":218,"ptt_exploit_capabilities":219},"Ni8mare","We found that the target server is running n8n, versions starting with 1.65.0 and below 1.121.0, which is vulnerable to an unauthenticated arbitrary file read that can be chained into remote code execution. n8n selects its request body parser based on the Content-Type header, but the Form Trigger handler consumes the uploaded file's filepath from the request body without first verifying that the request was actually a multipart\u002Fform-data upload. An unauthenticated attacker who reaches an active Form Trigger workflow with a file-upload field can therefore send a JSON body with a forged files object and set filepath to any path on the server, causing n8n to read that file and return it in the workflow response. By reading \u002Fproc\u002Fself\u002Fenviron, the instance encryption key from the .n8n\u002Fconfig file, and the SQLite database, the attacker recovers the owner account's credentials, forges an authenticated admin session cookie, and then abuses the expression-injection sandbox bypass (CVE-2025-68613) in a crafted workflow to execute arbitrary operating system commands.","n8n, versions starting with 1.65.0 and below 1.121.0, is vulnerable to an unauthenticated arbitrary file read that can be escalated to remote code execution. The Form Trigger endpoint reads an uploaded file's path from the request body without confirming the request was a genuine multipart upload, so an attacker can send a JSON body with a forged file object and read any file on the server. Using the leaked encryption key and database, the attacker can forge an administrator session and run arbitrary code on the underlying host.","Update n8n to version 1.121.0 or later.","We recommend updating n8n to version 1.121.0 or later; until the update can be applied, review any workflows that expose Form Trigger nodes to untrusted users and restrict network access to the n8n instance.",[209,210],"https:\u002F\u002Fthehackernews.com\u002F2026\u002F01\u002Fcritical-n8n-vulnerability-cvss-100.html","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-21858",10,0.78447,0.99574,[215],"CVE-2026-21858","2026-01-08T00:00:00Z","Workflow Automation","n8n",[145],"NETSCAN-SNIPER-CVE-2026-21858","n8n - Remote Code Execution",{"id":223,"detectable_with":224,"vuln_details":227,"vuln_id":247,"name":248,"published":196,"updated":196},29784,{"tool":225,"engine":226},{"id":82,"name":83},{"id":82,"name":122},{"id":223,"codename":228,"description":229,"severity":125,"risk_description":230,"public_description":231,"public_recommendation":232,"recommendation":233,"references":234,"cvssv3":211,"epss_score":238,"epss_percentile":239,"cve":240,"in_cisa_catalog":139,"date":242,"software_type":243,"vendor":244,"product":245,"ptt_exploit_capabilities":246},"StyleSmuggler","We found that the target is vulnerable to CVE-2026-75650 (\"StyleSmuggler\"), an unauthenticated remote code execution in Magento Open Source and Adobe Commerce. A PHP loader is first planted in a Magento error report via the \u002Fpaypal\u002Ftransparent\u002Fresponse\u002F endpoint, then admin email-preview directives are smuggled through a guest cart billing address. Triggering the failed-payment notification render reaches a gadget chain (ColumnSet -> Aws\\S3\\S3Client -> ArrayScanner) that includes and executes the poisoned report, allowing a remote unauthenticated attacker to run arbitrary PHP and OS commands on the server.","The risk exists that a remote unauthenticated attacker can fully compromise the server in order to steal confidential customer and payment information, install ransomware or pivot to the internal network.","Magento Open Source and Adobe Commerce are vulnerable to CVE-2026-75650 (\"StyleSmuggler\"), an unauthenticated server-side template injection that leads to remote code execution. A remote attacker can execute arbitrary code on the store without any authentication.","Apply the Adobe hotfix VULN-39341 (APSB26-146) and rotate all secrets and credentials.","We recommend applying the Adobe hotfix VULN-39341 (APSB26-146) immediately and, because the store may already be compromised, rotating the encryption key, admin passwords, API\u002Fintegration tokens, payment gateway and database credentials.",[235,236,237],"https:\u002F\u002Fhelpx.adobe.com\u002Fsecurity\u002Fproducts\u002Fmagento\u002Fapsb26-146.html","https:\u002F\u002Fsansec.io\u002Fresearch\u002Fstylesmuggler-0day","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-75650",0.03949,0.90094,[241],"CVE-2026-75650","2026-09-07T00:00:00Z","E-commerce Platform","Adobe","Magento \u002F Adobe Commerce",[145],"NETSCAN-SNIPER-CVE-2026-75650","Magento - Remote Code Execution",{"id":250,"detectable_with":251,"vuln_details":254,"vuln_id":274,"name":275,"published":196,"updated":196},29780,{"tool":252,"engine":253},{"id":82,"name":83},{"id":82,"name":122},{"id":250,"codename":76,"description":255,"severity":125,"risk_description":155,"public_description":256,"public_recommendation":257,"recommendation":258,"references":259,"cvssv3":264,"epss_score":265,"epss_percentile":266,"cve":267,"in_cisa_catalog":139,"date":269,"software_type":270,"vendor":271,"product":272,"ptt_exploit_capabilities":273},"We found that the target Joomla site is running the SP Page Builder extension, versions up to and including 6.6.1, which is vulnerable to an unauthenticated remote code execution. The vulnerability stems from a missing authentication check and a missing file-type restriction in the custom icon upload feature (com_sppagebuilder, task=asset.uploadCustomIcon): an unauthenticated attacker can submit a crafted icon-package ZIP archive, whose contents are extracted verbatim into a web-accessible directory (media\u002Fcom_sppagebuilder\u002Fassets\u002Ficonfont\u002F\u003Cname>\u002F) without any validation. By bundling a PHP file inside the archive, the attacker drops an executable script under the web root and can then execute arbitrary code by requesting the extracted file directly.","The SP Page Builder extension for Joomla, versions up to and including 6.6.1, is vulnerable to unauthenticated remote code execution due to an unrestricted file upload in its custom icon upload feature. An attacker can submit a crafted icon-package ZIP archive to the upload endpoint (com_sppagebuilder, task=asset.uploadCustomIcon), and the archive contents, including a bundled PHP file, are extracted into a web-accessible directory. Because the endpoint requires no authentication and performs insufficient validation, the extracted PHP file can be requested and executed remotely.","Update the SP Page Builder extension to version 6.6.2 or later.","We recommend updating the SP Page Builder extension to version 6.6.2 or later; if immediate update is not possible, disable or restrict the extension and ensure uploaded files are stored outside a web-executable location.",[260,261,262,263],"https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-48908","https:\u002F\u002Fmysites.guru\u002Fblog\u002Fsp-page-builder-zero-day-uploadcustomicon-rce\u002F","https:\u002F\u002Fgithub.com\u002Fpapageo75\u002FCVE-2026-48908-PoC","https:\u002F\u002Fwww.cisa.gov\u002Fknown-exploited-vulnerabilities-catalog",9.8,0.88512,0.9977,[268],"CVE-2026-48908","2026-06-20T00:00:00Z","Joomla Extension","JoomShaper","SP Page Builder",[145],"NETSCAN-SNIPER-CVE-2026-48908","Joomla SP Page Builder - Remote Code Execution",{"id":277,"detectable_with":278,"vuln_details":281,"vuln_id":300,"name":301,"published":196,"updated":196},29778,{"tool":279,"engine":280},{"id":82,"name":83},{"id":82,"name":122},{"id":277,"codename":76,"description":282,"severity":125,"risk_description":283,"public_description":284,"public_recommendation":285,"recommendation":286,"references":287,"cvssv3":290,"epss_score":291,"epss_percentile":292,"cve":293,"in_cisa_catalog":9,"date":295,"software_type":296,"vendor":297,"product":297,"ptt_exploit_capabilities":298},"We found that the target server is vulnerable to CVE-2026-19478, a vulnerability in the GitLab GraphQL API that lets an unauthenticated attacker run methods the schema does not expose. The \u003Ccode>@gl_introduced\u003C\u002Fcode> directive exists so that an older instance tolerates a field belonging to a newer GitLab release. When a query asks for an unknown field and marks it with a version newer than the running instance, GitLab builds that field at runtime from the name the attacker chose. The field is built without a resolver, so the GraphQL library answers it by calling the method with the same name on the underlying object, and the directive is handled before the permission checks run. We have detected this vulnerability by reading a publicly visible project through \u003Ccode>\u002Fapi\u002Fv4\u002Fprojects?visibility=public\u003C\u002Fcode>, and then asking the GraphQL API for a field of that project that its schema does not define, marked with a future version. The server answered with the value of the method instead of rejecting the field, which confirms that a method chosen by the attacker was executed on the project record.","The risk exists that a remote unauthenticated attacker can invoke internal methods of the application on public projects and users, read attributes that the API does not expose, and modify or delete projects and user accounts, which leads to loss of data and of the integrity of the hosted repositories.","GitLab is vulnerable to CVE-2026-19478, a vulnerability in the GraphQL API that lets an unauthenticated attacker run methods that the API is not meant to expose. A directive meant to keep older instances compatible with newer clients makes GitLab build a missing field at runtime, using the name supplied in the request, and answer it by calling the method with that name on the underlying record before any permission check is performed. Because this happens on objects that are readable by anyone, such as public projects and their users, a remote attacker can reach internal methods of the application and modify or delete public projects and user data.","Update GitLab to version 18.11.11, 19.0.8, 19.1.6 or 19.2.4, depending on the release series in use.","We recommend updating GitLab Community Edition or Enterprise Edition to version 18.11.11, 19.0.8, 19.1.6 or 19.2.4, depending on the release series in use, since these are the versions in which this vulnerability was fixed.",[288,289],"https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-19478","https:\u002F\u002Fdocs.gitlab.com\u002Freleases\u002Fpatches\u002Fpatch-release-gitlab-19-2-4-released\u002F",9.4,0.60204,0.99114,[294],"CVE-2026-19478","2026-08-17T00:00:00Z","DevOps Platform","GitLab",[299],"CUSTOM","NETSCAN-SNIPER-CVE-2026-19478","GitLab - Arbitrary Method Invocation",{"id":303,"detectable_with":304,"vuln_details":307,"vuln_id":322,"name":323,"published":196,"updated":196},29779,{"tool":305,"engine":306},{"id":82,"name":83},{"id":82,"name":122},{"id":303,"codename":76,"description":308,"severity":125,"risk_description":309,"public_description":310,"public_recommendation":311,"recommendation":312,"references":313,"cvssv3":211,"epss_score":316,"epss_percentile":317,"cve":318,"in_cisa_catalog":139,"date":320,"software_type":296,"vendor":297,"product":297,"ptt_exploit_capabilities":321},"We found that the target server is vulnerable to CVE-2026-85706, an arbitrary file read vulnerability in the GitLab repository API that requires no authentication. GitLab Workhorse matches its interception rules against the escaped URL path, while Rails routes the decoded path. Percent-encoding a single character of a static route segment, such as \u003Ccode>\u002Fapi\u002Fv4\u002Fprojects\u002F1\u002Frepository\u002F%66iles\u002Fx\u003C\u002Fcode>, or simply appending a trailing slash, therefore makes Workhorse skip the request instead of rewriting it. The upload metadata that Workhorse normally generates is then accepted straight from the query string, and the Rails handler opens the local path given in \u003Ccode>file.path\u003C\u002Fcode> before any authentication check runs. We have detected this vulnerability by sending such a request with a \u003Ccode>file.path\u003C\u002Fcode> value pointing to a file that does not exist on the target, and confirming that the server reports the missing local file instead of rejecting the request as unauthenticated, then by reading a GitLab application source file from the server. The file is read with the privileges of the account that runs GitLab, and its content is returned inside the error raised while the server parses that content as form data.","The risk exists that a remote unauthenticated attacker can read configuration files, application source code and log files from the GitLab server, and use the credentials, tokens and other confidential information they contain to further compromise the system.","GitLab is vulnerable to CVE-2026-85706, an arbitrary file read vulnerability in the repository API that requires no authentication. GitLab Workhorse and Rails disagree on how an encoded URL path is interpreted, so a request that percent-encodes one character of the route escapes the processing Workhorse normally performs. The upload metadata is then taken directly from the request, and the server opens the local file named by the attacker before verifying who is asking. This allows a remote unauthenticated attacker to read files belonging to the GitLab installation, such as configuration files, application source code and log files, with the privileges of the account that runs GitLab.","Update GitLab to version 19.3.2, 19.2.6 or 19.1.8, depending on the release series in use.","We recommend updating GitLab Community Edition or Enterprise Edition to version 19.3.2, 19.2.6 or 19.1.8, depending on the release series in use, since these are the versions in which this vulnerability was fixed.",[314,315],"https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-85706","https:\u002F\u002Fdocs.gitlab.com\u002Freleases\u002Fpatches\u002Fpatch-release-gitlab-19-3-2-released\u002F",0.92956,0.9983,[319],"CVE-2026-85706","2026-09-10T00:00:00Z",[299],"NETSCAN-SNIPER-CVE-2026-85706","GitLab - Arbitrary File Read",{"id":325,"detectable_with":326,"vuln_details":329,"vuln_id":349,"name":350,"published":196,"updated":196},29782,{"tool":327,"engine":328},{"id":82,"name":83},{"id":82,"name":122},{"id":325,"codename":76,"description":330,"severity":125,"risk_description":331,"public_description":332,"public_recommendation":333,"recommendation":334,"references":335,"cvssv3":339,"epss_score":340,"epss_percentile":341,"cve":342,"in_cisa_catalog":139,"date":344,"software_type":345,"vendor":346,"product":347,"ptt_exploit_capabilities":348},"We found that the target is vulnerable to CVE-2026-87902, an unauthenticated path traversal in the WordPress core page-template resolution (get_page_template). By combining a valid page_id with a double-encoded traversal in the pagename parameter, a remote unauthenticated attacker can make WordPress include and execute an arbitrary local PHP file outside the active theme directory. On servers where PEAR's pearcmd.php is present and register_argc_argv is enabled, this local file inclusion is escalated to remote code execution.","The risk exists that a remote unauthenticated attacker can include and execute local files and, on affected server configurations, fully compromise the server in order to steal confidential information, install ransomware or pivot to the internal network.","WordPress Core is vulnerable to CVE-2026-87902, an unauthenticated path traversal in its page-template resolution that allows a remote attacker to include and execute arbitrary local PHP files outside the active theme. On servers where PEAR's pearcmd.php is available, this can be escalated to remote code execution.","Update WordPress to version 7.1.2 or later.","We recommend updating WordPress to version 7.1.2 or later, or to the corresponding patched release for your branch (7.0.6, 6.9.9, 6.8.10, 6.7.9, 6.6.9, down to 4.7.37).",[336,337,338],"https:\u002F\u002Fgithub.com\u002Fadvisories\u002FGHSA-7hp8-65ch-5whp","https:\u002F\u002Fpatchstack.com\u002Farticles\u002Fcve-2026-87902-attackers-started-probing-wordpress-sites-hours-after-the-patch\u002F","https:\u002F\u002Fwww.helpnetsecurity.com\u002F2026\u002F09\u002F23\u002Fcve-2026-87902-wordpress-7-1-2-security-release\u002F",9.2,0.45501,0.98756,[343],"CVE-2026-87902","2026-09-22T00:00:00Z","Content Management System (CMS)","WordPress","WordPress Core",[145],"NETSCAN-SNIPER-CVE-2026-87902","WordPress Core - Remote Code Execution",{"id":352,"detectable_with":353,"vuln_details":356,"vuln_id":373,"name":374,"published":196,"updated":196},29781,{"tool":354,"engine":355},{"id":82,"name":83},{"id":82,"name":122},{"id":352,"codename":76,"description":357,"severity":125,"risk_description":155,"public_description":358,"public_recommendation":359,"recommendation":360,"references":361,"cvssv3":264,"epss_score":365,"epss_percentile":366,"cve":367,"in_cisa_catalog":139,"date":369,"software_type":270,"vendor":370,"product":371,"ptt_exploit_capabilities":372},"We found that the target Joomla site is running the Page Builder CK extension, versions up to and including 3.5.10, which is vulnerable to an unauthenticated remote code execution. The vulnerability stems from a missing authentication check and a disabled file-type allow-list in the image handling feature (com_pagebuilderck, task=browse.ajaxAddPicture): an unauthenticated attacker can submit a crafted multipart\u002Fform-data request to the upload endpoint and store an arbitrary file, including executable PHP, under the attacker-controlled web-accessible path (for example media\u002Fcom_pagebuilderck\u002Fgfonts\u002F) without any file-type or content validation. Because the uploaded file is stored in a location directly served by the web server, the attacker can execute arbitrary code by requesting the uploaded file directly.","The Page Builder CK extension for Joomla, versions up to and including 3.5.10, is vulnerable to unauthenticated remote code execution due to an unrestricted file upload in its image handling feature. An attacker can submit a crafted multipart\u002Fform-data request to the upload endpoint (com_pagebuilderck, task=browse.ajaxAddPicture) and store a PHP file under a web-accessible directory. Because the endpoint requires no authentication and performs insufficient validation, the uploaded PHP file can be requested and executed remotely.","Update the Page Builder CK extension to version 3.6.0 or later.","We recommend updating the Page Builder CK extension to version 3.6.0 or later; if immediate update is not possible, disable or restrict the extension and ensure uploaded files are stored outside a web-executable location.",[362,363,364,263],"https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-56290","https:\u002F\u002Fcxsecurity.com\u002Fissue\u002FWLB-2026070010","https:\u002F\u002Fwww.exploit-db.com\u002Fexploits\u002F52626",0.30866,0.98205,[368],"CVE-2026-56290","2026-06-29T00:00:00Z","Joomlack","Page Builder CK",[145],"NETSCAN-SNIPER-CVE-2026-56290","Joomla Page Builder CK - Remote Code Execution",{"id":376,"detectable_with":377,"vuln_details":380,"vuln_id":395,"name":396,"published":397,"updated":76},29770,{"tool":378,"engine":379},{"id":82,"name":83},{"id":85,"name":86},{"id":376,"codename":76,"description":76,"severity":125,"risk_description":381,"public_description":382,"public_recommendation":383,"recommendation":76,"references":384,"cvssv3":264,"epss_score":388,"epss_percentile":389,"cve":390,"in_cisa_catalog":9,"date":392,"software_type":76,"vendor":393,"product":394,"ptt_exploit_capabilities":76},"Unauthenticated attackers can invoke all MCP tools exposed by the server, read arbitrary local files including \u002Fproc\u002Fself\u002Fenviron, and recover the configured GITLAB_PERSONAL_ACCESS_TOKEN, leading to full GitLab account takeover.","The @zereight\u002Fmcp-gitlab GitLab MCP server exposes its SSE transport endpoints without any authentication when SSE mode is enabled. An unauthenticated attacker with network access can establish an MCP session and invoke every registered tool, including upload_markdown, which reads arbitrary files from the server filesystem via an unsanitized file_path parameter.","Update to @zereight\u002Fmcp-gitlab 2.1.27 or later, set SSE_AUTH_TOKEN, and bind the service to a loopback address.",[385,386,387],"https:\u002F\u002Fgithub.com\u002Fzereight\u002Fgitlab-mcp\u002Fsecurity\u002Fadvisories\u002FGHSA-cv3r-c5h8-f4g5","https:\u002F\u002Fgithub.com\u002Fzereight\u002Fgitlab-mcp\u002Fcommit\u002Fe436ee4ad067b64584ec9312c9e9c9a2641c1976","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-61560",0.02901,0.86478,[391],"CVE-2026-61560","2026-09-15T00:00:00Z","zereight","gitlab-mcp","NETSCAN-NUCLEI-CVE-CVE-2026-61560","GitLab MCP Server \u003C 2.1.27 - Unauthenticated SSE Transport Access","2026-09-28T00:00:00Z",{"id":399,"detectable_with":400,"vuln_details":403,"vuln_id":423,"name":424,"published":397,"updated":76},29772,{"tool":401,"engine":402},{"id":82,"name":83},{"id":85,"name":86},{"id":399,"codename":76,"description":76,"severity":91,"risk_description":404,"public_description":405,"public_recommendation":406,"recommendation":76,"references":407,"cvssv3":416,"epss_score":417,"epss_percentile":418,"cve":419,"in_cisa_catalog":9,"date":421,"software_type":76,"vendor":422,"product":422,"ptt_exploit_capabilities":76},"Unauthenticated remote attackers can read arbitrary files from all Dolibarr managed directories, potentially exposing database credentials, invoices, contracts, and other sensitive data.","Dolibarr ERP\u002FCRM versions 23.0.4 through 24.0.0 contain an authorization bypass vulnerability in document.php and viewimage.php. The public share-link feature forces NOLOGIN when hashp is present, but the value 'shared' skips token resolution while the override still fires for any non-empty hashp value. This bypass allows unauthenticated remote attackers to read arbitrary files from all Dolibarr managed directories including logs, SQL database backups, invoices, contracts, user vcards, and custom module sources.","Upgrade Dolibarr to version 24.0.1 or later.",[408,409,410,411,412,413,414,415],"https:\u002F\u002Fgithub.com\u002FFaceless0x7\u002FCVE-2026-89013","https:\u002F\u002Fgithub.com\u002FDolibarr\u002Fdolibarr\u002Fcommit\u002Fcd05688dbed8a4af6eef32faf4fc1e823a37bce9","https:\u002F\u002Fgithub.com\u002FDolibarr\u002Fdolibarr\u002Fcommit\u002Fa8bc4a63e1b6356884abcd83c4a38954d9649b0b","https:\u002F\u002Fgithub.com\u002FDolibarr\u002Fdolibarr\u002Fcommit\u002F3bd8aa8b909e596d7dab4388d0466ec24e6ad191","https:\u002F\u002Fgithub.com\u002FDolibarr\u002Fdolibarr\u002Freleases\u002Ftag\u002F24.0.1","https:\u002F\u002Fwww.vulncheck.com\u002Fadvisories\u002Fdolibarr-authorization-bypass-via-hashp-parameter-in-document-php","https:\u002F\u002Fprevidian.com\u002FCVE-2026-89013","http:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-89013",7.5,0.0156,0.74345,[420],"CVE-2026-89013","2026-09-11T00:00:00Z","dolibarr","NETSCAN-NUCLEI-CVE-CVE-2026-89013","Dolibarr \u003C 24.0.0 - Authorization Bypass via hashp Parameter",{"id":426,"detectable_with":427,"vuln_details":430,"vuln_id":445,"name":446,"published":397,"updated":76},29771,{"tool":428,"engine":429},{"id":82,"name":83},{"id":85,"name":86},{"id":426,"codename":76,"description":76,"severity":125,"risk_description":431,"public_description":432,"public_recommendation":433,"recommendation":76,"references":434,"cvssv3":264,"epss_score":438,"epss_percentile":439,"cve":440,"in_cisa_catalog":9,"date":442,"software_type":76,"vendor":443,"product":444,"ptt_exploit_capabilities":76},"The risk exists that a remote unauthenticated attacker could exploit this vulnerability to read sensitive information from arbitrary files located on the file system of the server.","Visual Composer Website Builder for WordPress \u003C= 45.16.0 contains a local file inclusion vulnerability caused by improper validation of the vcv-template parameter, letting unauthenticated attackers include and execute arbitrary files, exploit requires no authentication.","Update to the latest version beyond 45.16.0.",[435,436,437],"https:\u002F\u002Fwww.wordfence.com\u002Fthreat-intel\u002Fvulnerabilities\u002Fwordpress-plugins\u002Fvisualcomposer\u002Fvisual-composer-website-builder-45160-unauthenticated-local-file-inclusion-via-vcv-template-parameter","https:\u002F\u002Fgithub.com\u002Fmurrez\u002FCVE-2026-12227","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-12227",0.02868,0.86314,[441],"CVE-2026-12227","2026-09-24T00:00:00Z","developer","visualcomposer","NETSCAN-NUCLEI-CVE-CVE-2026-12227","Visual Composer \u003C= 45.16.0 - Unauthenticated LFI",{"id":448,"detectable_with":449,"vuln_details":452,"vuln_id":467,"name":468,"published":442,"updated":76},29768,{"tool":450,"engine":451},{"id":82,"name":83},{"id":85,"name":86},{"id":448,"codename":76,"description":76,"severity":91,"risk_description":453,"public_description":454,"public_recommendation":455,"recommendation":76,"references":456,"cvssv3":416,"epss_score":460,"epss_percentile":461,"cve":462,"in_cisa_catalog":9,"date":464,"software_type":76,"vendor":465,"product":466,"ptt_exploit_capabilities":76},"Unauthenticated attackers can execute arbitrary SQL against the WordPress database.","Asgaros Forum for WordPress versions prior to 3.2.0 is vulnerable to unauthenticated SQL injection through the asgarosforum_unread_exclude cookie. The cookie is JSON-decoded and its object keys are imploded into a NOT IN() clause without sanitisation. The vulnerable query only runs while rendering the forum page, so the payload must be sent there rather than to the site root.","Update Asgaros Forum to 3.2.0 or later.",[457,458,459],"https:\u002F\u002Fwpscan.com\u002Fvulnerability\u002Fe89f1f31-dc70-4ea5-b389-81c8be5b10c6\u002F","https:\u002F\u002Fplugins.trac.wordpress.org\u002Fbrowser\u002Fasgaros-forum\u002Ftrunk\u002Fincludes\u002Fforum-unread.php","https:\u002F\u002Fcve.mitre.org\u002Fcgi-bin\u002Fcvename.cgi?name=CVE-2025-11452",0.01217,0.67537,[463],"CVE-2025-11452","2025-11-08T00:00:00Z","asgaros","asgaros-forum","NETSCAN-NUCLEI-CVE-CVE-2025-11452","Asgaros Forum \u003C 3.2.0 - SQL Injection",{"id":470,"detectable_with":471,"vuln_details":474,"vuln_id":488,"name":489,"published":442,"updated":76},29766,{"tool":472,"engine":473},{"id":82,"name":83},{"id":85,"name":86},{"id":470,"codename":76,"description":76,"severity":91,"risk_description":475,"public_description":476,"public_recommendation":477,"recommendation":76,"references":478,"cvssv3":483,"epss_score":484,"epss_percentile":485,"cve":486,"in_cisa_catalog":9,"date":344,"software_type":76,"vendor":76,"product":76,"ptt_exploit_capabilities":76},"Remote attackers can bypass API-key validation to use LLM providers, consume paid credits, and enumerate models without authorization.","9Router prior to 0.5.6 contains an authentication bypass caused by trusting client-supplied X-9r-Real-Ip header in src\u002FdashboardGuard.js, letting remote unauthenticated attackers access local API routes and consume resources, exploit requires bypassing API-key validation via header manipulation.","Update to version 0.5.6 or later.",[479,480,481,482],"https:\u002F\u002Fgithub.com\u002Fadvisories\u002FGHSA-5mj8-gf6m-fhw8","https:\u002F\u002Fgithub.com\u002Fdecolua\u002F9router\u002Fsecurity\u002Fadvisories\u002FGHSA-5mj8-gf6m-fhw8","https:\u002F\u002Fgithub.com\u002Fdecolua\u002F9router\u002Fcommit\u002Fefd20be8d81ef2e256a7037f3aa78e6b567b5fd3","https:\u002F\u002Fgithub.com\u002Fdecolua\u002F9router\u002Freleases\u002Ftag\u002Fv0.5.6",7.3,0.00968,0.60488,[487],"CVE-2026-56681","NETSCAN-NUCLEI-CVE-CVE-2026-56681","9router \u003C=0.5.4 - Authentication Bypass",{"id":491,"detectable_with":492,"vuln_details":495,"vuln_id":510,"name":511,"published":442,"updated":76},29767,{"tool":493,"engine":494},{"id":82,"name":83},{"id":85,"name":86},{"id":491,"codename":76,"description":76,"severity":91,"risk_description":155,"public_description":496,"public_recommendation":497,"recommendation":76,"references":498,"cvssv3":502,"epss_score":503,"epss_percentile":504,"cve":505,"in_cisa_catalog":9,"date":507,"software_type":76,"vendor":508,"product":509,"ptt_exploit_capabilities":76},"Blue Angel 5V Technologies Blue Angel Software Suite through 20230920, as used in Analog Telephone Adapter (ATA) and Voice over IP (VoIP) devices, allows remote authenticated attackers to execute arbitrary OS commands as root via shell metacharacters in the ping_addr parameter to webctrl.cgi?action=pingtest_update.","Change default credentials, block management ports (e.g. 9000), update firmware, and restrict admin access to trusted networks.",[499,500,501],"https:\u002F\u002Fwww.exploit-db.com\u002Fexploits\u002F46792","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2025-34033","http:\u002F\u002Fwww.5vtechnologies.com",8.8,0.11206,0.95838,[506],"CVE-2025-34033","2025-06-24T00:00:00Z","5vtechnologies","blue_angel_software_suite","NETSCAN-NUCLEI-CVE-CVE-2025-34033","Blue Angel Software Suite (5V Technologies) - OS Command Injection",{"id":513,"detectable_with":514,"vuln_details":517,"vuln_id":531,"name":532,"published":442,"updated":76},29763,{"tool":515,"engine":516},{"id":82,"name":83},{"id":85,"name":86},{"id":513,"codename":76,"description":76,"severity":125,"risk_description":155,"public_description":518,"public_recommendation":519,"recommendation":76,"references":520,"cvssv3":264,"epss_score":524,"epss_percentile":525,"cve":526,"in_cisa_catalog":139,"date":528,"software_type":76,"vendor":529,"product":530,"ptt_exploit_capabilities":76},"Ray versions prior to 2.52.0 allow unauthenticated remote code execution via the job submission API at \u002Fapi\u002Fjobs\u002F. A weak User-Agent heuristic (rejecting Mozilla-prefixed headers) can be bypassed by non-browser clients, enabling arbitrary command execution when the dashboard is network-reachable.","Upgrade Ray to version 2.52.0 or later and enable RAY_AUTH_MODE=token. Restrict dashboard access to trusted networks.",[521,522,523],"https:\u002F\u002Fgithub.com\u002Fray-project\u002Fray\u002Fsecurity\u002Fadvisories\u002FGHSA-q279-jhrf-cc6v","https:\u002F\u002Fgithub.com\u002Fprojectdiscovery\u002Fnuclei-templates\u002Fissues\u002F16961","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2025-62593",0.62459,0.99166,[527],"CVE-2025-62593","2025-11-26T00:00:00Z","ray_project","ray","NETSCAN-NUCLEI-CVE-CVE-2025-62593","Ray \u003C 2.52.0 - Remote Code Execution",{"id":534,"detectable_with":535,"vuln_details":538,"vuln_id":554,"name":555,"published":442,"updated":76},29764,{"tool":536,"engine":537},{"id":82,"name":83},{"id":85,"name":86},{"id":534,"codename":76,"description":76,"severity":91,"risk_description":539,"public_description":540,"public_recommendation":541,"recommendation":76,"references":542,"cvssv3":483,"epss_score":547,"epss_percentile":548,"cve":549,"in_cisa_catalog":9,"date":551,"software_type":76,"vendor":552,"product":553,"ptt_exploit_capabilities":76},"Remote attackers can access sensitive information from the manager API, potentially exposing confidential data.","NeuVector through 5.4.9 contains an information disclosure vulnerability caused by missing authentication and cached sensitive data in the manager \u002Fnetwork\u002Fgraph API, letting remote attackers access sensitive information, exploit requires no special privileges.","Update to the latest version beyond 5.4.9.",[543,544,545,546],"https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-25703","https:\u002F\u002Fgithub.com\u002Fneuvector\u002Fmanager\u002Fsecurity\u002Fadvisories\u002FGHSA-hx45-873x-74qv","https:\u002F\u002Fgithub.com\u002Fneuvector\u002Fmanager\u002Fcommit\u002F949cc1184fdf671416f788d9d2a039f8558a717d","https:\u002F\u002Fgithub.com\u002Fneuvector\u002Fmanager\u002Freleases\u002Ftag\u002Fv5.5.0",0.00804,0.55186,[550],"CVE-2026-25703","2026-08-05T00:00:00Z","suse","neuvector-manager","NETSCAN-NUCLEI-CVE-CVE-2026-25703","NeuVector - Information Disclosure",{"id":557,"detectable_with":558,"vuln_details":561,"vuln_id":581,"name":582,"published":442,"updated":76},29765,{"tool":559,"engine":560},{"id":82,"name":83},{"id":85,"name":86},{"id":557,"codename":76,"description":76,"severity":91,"risk_description":562,"public_description":563,"public_recommendation":564,"recommendation":76,"references":565,"cvssv3":573,"epss_score":574,"epss_percentile":575,"cve":576,"in_cisa_catalog":139,"date":578,"software_type":76,"vendor":579,"product":580,"ptt_exploit_capabilities":76},"An admin technician (or a low-privileged technician who first escalates via CVE-2024-57726 ) can write a crafted zip entry to any path on the host - a crontab on Linux, a replaced executable or DLL on Windows - and obtain remote code execution as the SimpleHelp server user, the chain ransomware operators such as Medusa and DragonForce used to take over managed estates.","SimpleHelp remote support software v5.5.7 and before allows admin users to upload arbitrary files anywhere on the file system by uploading a crafted zip file (i.e. zip slip). This can be exploited to execute arbitrary code on the host in the context of the SimpleHelp server user. This template is a version-based check: it reads the version banner exposed by the vendor's own \u002Fallversions page and flags branches that predate the January 2025 fixes.","Upgrade SimpleHelp to 5.5.8 or later (or apply the vendor's 070125 patch to the 5.4.10 and 5.3.9 branches), then rotate all administrator and technician passwords and restrict the source IP addresses allowed to log in.",[566,567,568,569,570,571,572],"https:\u002F\u002Fsimple-help.com\u002Fkb---security-vulnerabilities-01-2025#security-vulnerabilities-in-simplehelp-5-5-7-and-earlier","https:\u002F\u002Fwww.horizon3.ai\u002Fattack-research\u002Fdisclosures\u002Fcritical-vulnerabilities-in-simplehelp-remote-support-software\u002F","https:\u002F\u002Fguides.simple-help.com\u002Fkb---checking-the-version-and-build-of-your-simplehelp-server","https:\u002F\u002Fwww.cisa.gov\u002Fknown-exploited-vulnerabilities-catalog?field_cve=CVE-2024-57728","https:\u002F\u002Fwww.microsoft.com\u002Fen-us\u002Fsecurity\u002Fblog\u002F2026\u002F04\u002F06\u002Fstorm-1175-focuses-gaze-on-vulnerable-web-facing-assets-in-high-tempo-medusa-ransomware-operations\u002F","https:\u002F\u002Fwww.trendmicro.com\u002Fvinfo\u002Fus\u002Fsecurity\u002Fnews\u002Fransomware-spotlight\u002Fransomware-spotlight-dragonforce","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2024-57728",7.2,0.64664,0.99222,[577],"CVE-2024-57728","2025-01-15T00:00:00Z","simple-help","simplehelp","NETSCAN-NUCLEI-CVE-CVE-2024-57728","SimpleHelp \u003C= 5.5.7 - Arbitrary File Upload",{"id":584,"detectable_with":585,"vuln_details":588,"vuln_id":597,"name":598,"published":442,"updated":76},29769,{"tool":586,"engine":587},{"id":82,"name":83},{"id":85,"name":86},{"id":584,"codename":76,"description":76,"severity":125,"risk_description":431,"public_description":589,"public_recommendation":590,"recommendation":76,"references":591,"cvssv3":339,"epss_score":340,"epss_percentile":341,"cve":595,"in_cisa_catalog":139,"date":344,"software_type":76,"vendor":596,"product":596,"ptt_exploit_capabilities":76},"An unauthenticated attacker can make `get_page_template()` page-template resolution include a chosen readable local `.php` file outside the active theme directories. If relevant pre-conditions for both the server and the active theme are met, this can lead to RCE.","Update WordPress to a patched maintenance release for the installed branch.",[592,593,594],"https:\u002F\u002Fgithub.com\u002FWordPress\u002Fwordpress-develop\u002Fsecurity\u002Fadvisories\u002FGHSA-7hp8-65ch-5whp","https:\u002F\u002Fgithub.com\u002FWordPress\u002FWordPress\u002Fcommit\u002Ffdeab470f4b4062462cf8ccdc788f258683c2d6f","https:\u002F\u002Fhadrian.io\u002Fvulnerability-alerts\u002Fcve-2026-87902-working-poc-wordpress-critical-path-traversal",[343],"wordpress","NETSCAN-NUCLEI-CVE-CVE-2026-87902","WordPress Core - PHP Template Path Traversal",{"id":600,"detectable_with":601,"vuln_details":604,"vuln_id":619,"name":620,"published":621,"updated":76},29762,{"tool":602,"engine":603},{"id":82,"name":83},{"id":85,"name":86},{"id":600,"codename":76,"description":76,"severity":91,"risk_description":605,"public_description":606,"public_recommendation":607,"recommendation":76,"references":608,"cvssv3":611,"epss_score":612,"epss_percentile":613,"cve":614,"in_cisa_catalog":9,"date":616,"software_type":76,"vendor":617,"product":618,"ptt_exploit_capabilities":76},"Unauthenticated attackers can read sensitive customer booking data and inject messages into conversations, compromising privacy and data integrity.","Bookly WordPress plugin \u003C= 28.1 contains an insecure direct object reference caused by missing validation on 'conversation_id' parameter, letting unauthenticated attackers read and inject messages into any AI booking conversation, exploit requires no authentication.","Update to the latest version beyond 28.1.",[609,610],"https:\u002F\u002Fwww.wordfence.com\u002Fthreat-intel\u002Fvulnerabilities\u002Fwordpress-plugins\u002Fbookly-responsive-appointment-booking-tool\u002Fonline-scheduling-and-appointment-booking-system-281-insecure-direct-object-reference-to-unauthenticated-sensitive-data-access-and-message-injection-via-conversation-id-parameter","https:\u002F\u002Fwww.cve.org\u002FCVERecord?id=CVE-2026-89063",8.2,0.01628,0.7533,[615],"CVE-2026-89063","2026-09-16T00:00:00Z","bookly","bookly-responsive-appointment-booking-tool","NETSCAN-NUCLEI-CVE-CVE-2026-89063","Bookly \u003C=28.1 - IDOR Unauthenticated Sensitive Data Access","2026-09-23T00:00:00Z",{"id":623,"detectable_with":624,"vuln_details":627,"vuln_id":642,"name":643,"published":344,"updated":76},29757,{"tool":625,"engine":626},{"id":82,"name":83},{"id":85,"name":86},{"id":623,"codename":76,"description":76,"severity":91,"risk_description":431,"public_description":628,"public_recommendation":629,"recommendation":76,"references":630,"cvssv3":611,"epss_score":635,"epss_percentile":636,"cve":637,"in_cisa_catalog":9,"date":639,"software_type":76,"vendor":640,"product":641,"ptt_exploit_capabilities":76},"Cockpit CMS through 2.14.0 contains a path traversal and local file inclusion (LFI) vulnerability when executed under PHP's built-in CLI server (PHP_SAPI == 'cli-server') or non-normalizing reverse proxies. The application fails to sanitize dot-dot sequences in PATH_INFO routes starting with '\u002F:' and containing '\u002Fstorage\u002F'. Unauthenticated remote attackers can traverse outside the designated directory to read arbitrary system files.","Upgrade to Cockpit CMS version 2.14.1 or higher.",[631,632,633,634],"https:\u002F\u002Fwww.cve.org\u002FCVERecord?id=CVE-2026-58467","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-58467","https:\u002F\u002Fgithub.com\u002Fcockpit-hq\u002Fcockpit\u002Fcompare\u002F2.14.0...2.14.1","https:\u002F\u002Fgithub.com\u002Fgeo-chen\u002Foss\u002Fblob\u002Fmain\u002Fcockpit.md",0.0173,0.76783,[638],"CVE-2026-58467","2026-07-02T00:00:00Z","cockpit-hq","cockpit","NETSCAN-NUCLEI-CVE-CVE-2026-58467","Cockpit CMS \u003C= 2.14.0 - Path Traversal \u002F Local File Inclusion",{"id":645,"detectable_with":646,"vuln_details":649,"vuln_id":658,"name":659,"published":344,"updated":76},29756,{"tool":647,"engine":648},{"id":82,"name":83},{"id":85,"name":86},{"id":645,"codename":76,"description":76,"severity":179,"risk_description":650,"public_description":651,"public_recommendation":652,"recommendation":76,"references":653,"cvssv3":76,"epss_score":76,"epss_percentile":76,"cve":76,"in_cisa_catalog":9,"date":76,"software_type":76,"vendor":657,"product":657,"ptt_exploit_capabilities":76},"The risk exists that the data is unknowingly exposed to the internet, making it accessible to remote threat actors that can leverage it to attack the target, or the entire company, depending on the sensitivity of the data.","Qdrant ships with no API key configured. When service.api_key is unset, the internal \u002Ftelemetry endpoint answers unauthenticated requests and returns the instance UUID, the running Qdrant version, the number of collections, the cluster configuration, and per-endpoint REST and gRPC request statistics. Reaching this endpoint without a credential also proves that no API key is enforced on the instance at all, since Qdrant gates \u002Ftelemetry behind the same key as the rest of its REST API.","Set service.api_key (and read_only_api_key where a read role is needed) so Qdrant enforces authentication on the REST and gRPC APIs, enable TLS, and keep port 6333 behind an authenticated network boundary rather than on a public interface.",[654,655,656],"https:\u002F\u002Fqdrant.tech\u002Fdocumentation\u002Fguides\u002Fsecurity\u002F","https:\u002F\u002Fapi.qdrant.tech\u002Fapi-reference\u002Fservice\u002Ftelemetry","https:\u002F\u002Fgithub.com\u002Fqdrant\u002Fqdrant","qdrant","NETSCAN-NUCLEI-EXPOSURES-QDRANT-TELEMETRY-EXPOSURE","Qdrant - Telemetry Exposure",{"id":661,"detectable_with":662,"vuln_details":665,"vuln_id":680,"name":681,"published":344,"updated":76},29758,{"tool":663,"engine":664},{"id":82,"name":83},{"id":85,"name":86},{"id":661,"codename":76,"description":76,"severity":125,"risk_description":666,"public_description":667,"public_recommendation":668,"recommendation":76,"references":669,"cvssv3":339,"epss_score":674,"epss_percentile":675,"cve":676,"in_cisa_catalog":9,"date":678,"software_type":76,"vendor":679,"product":679,"ptt_exploit_capabilities":76},"An unauthenticated attacker can recover the full admin email address and password-reset token, enabling direct account takeover without any existing credentials.","Strapi versions starting in 4.0.0 and prior to 5.37.0 did not sufficiently sanitize query parameters when filtering content via relational fields. An attacker could use the `where` query parameter on any publicly-accessible content-type with an `updatedBy` field to perform a boolean-oracle attack against private fields on the joined admin_users table, including the resetPasswordToken field, enabling full administrative account takeover without authentication.","Upgrade Strapi to version 5.37.0 or later. The patch introduces explicit query-parameter sanitization via strictParam, addQueryParams, and addBodyParams primitives that reject operator chains traversing into restricted relational targets before reaching the database.",[670,671,672,673],"https:\u002F\u002Fgithub.com\u002Fstrapi\u002Fstrapi\u002Fsecurity\u002Fadvisories","https:\u002F\u002Fbishopfox.com\u002Fblog\u002Fcve-2026-27886-unauthenticated-boolean-oracle-exfiltration-of-administrator-secrets-in-strapi","https:\u002F\u002Fgithub.com\u002FBishopFox\u002FCVE-2026-27886-check","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-27886",0.02519,0.84292,[677],"CVE-2026-27886","2026-05-14T00:00:00Z","strapi","NETSCAN-NUCLEI-CVE-CVE-2026-27886","Strapi \u003C=5.36.x - Admin Credential Enumeration"]