[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"all-banners":3,"SkipToContent_34xgpJIRRkpiT6ls6jE4NHf7VpvQCQBEwi69exi4oT0":44,"FormattedDate_YGZoki4KbemRpkMkk2LxWIughCHzKqWyXU32hDxuo":51,"FooterNav_JsYsxvLufb1W12aeknKZ89on0MD0bNDTiB5EYxyxmU":58,"FooterSocial_u16tCafBUeGMoDrdLfTINytP2JB5msc6iB3VDUutAoU":64,"$f2r4b9phgo6bha":71,"$f17q7jdn7tll3p":73,"finding-templates-{\"q\":\"\",\"page\":1}":108},[4,15,21,27,33,39],{"title":5,"slug":6,"text":7,"link":8,"external":9,"targets":10,"cta":12,"variant":13,"campaign_id":14},"Compliance - Page Launch - Network Scanner","compliance-pages-launch-network-scanner","Scheduled scans are the spine of every compliance framework. Are you audit-ready?","https:\u002F\u002Fpentest-tools.com\u002Fusage\u002Fcompliance",false,[11],"\u002Fnetwork-vulnerability-scanning\u002Fnetwork-security-scanner-online","Get compliance evidence","secondary","compliance-pages-launch",{"title":16,"slug":17,"text":18,"link":8,"external":9,"targets":19,"cta":12,"variant":13,"campaign_id":14},"Compliance - Page Launch - Website Scanner","compliance-pages-launch-website-scanner","Authenticated web-app scans show up in SOC 2, NIS2, and CRA Annex I. See why this is crucial for the business.",[20],"\u002Fwebsite-vulnerability-scanning\u002Fwebsite-scanner",{"title":22,"slug":23,"text":24,"link":8,"external":9,"targets":25,"cta":12,"variant":13,"campaign_id":14},"Compliance - Page Launch - Advanced Pentest Reporting","compliance-pages-launch-reporting","Editable DOCX. Immutable PDF. JSON for the GRC tool. See why these formats are on every auditor's checklist.",[26],"\u002Ffeatures\u002Fpentest-reporting",{"title":28,"slug":29,"text":30,"link":8,"external":9,"targets":31,"cta":12,"variant":13,"campaign_id":14},"Compliance - Page Launch - Integrations","compliance-pages-launch-integrations","Vanta, Jira, webhooks - they all route back to DORA, NIS2, SOC 2, ISO 27001, CRA. See why this is crucial for the business.",[32],"\u002Ffeatures\u002Fintegrations",{"title":34,"slug":35,"text":36,"link":8,"external":9,"targets":37,"cta":12,"variant":13,"campaign_id":14},"Compliance - Page Launch - Sniper","compliance-pages-launch-sniper","Five compliance framework pages now reference Sniper as the source of validated exploitability evidence. See them all.",[38],"\u002Fexploit-helpers\u002Fsniper",{"title":40,"slug":14,"text":41,"link":8,"external":9,"targets":42,"cta":12,"variant":13,"campaign_id":14},"Compliance - Page Launch - Homepage","Turn confirmed vulnerabilities into evidence your auditor accepts. Testing requirements for DORA, NIS2, SOC 2, ISO 27001, and CRA.",[43],"\u002F",["Island",45],{"key":46,"params":47,"result":49},"SkipToContent_34xgpJIRRkpiT6ls6jE4NHf7VpvQCQBEwi69exi4oT0",{"props":48},"{}",{"head":50},{},["Island",52],{"key":53,"params":54,"result":56},"FormattedDate_YGZoki4KbemRpkMkk2LxWIughCHzKqWyXU32hDxuo",{"props":55},"{\"date\":1778569448,\"format\":\"MMMM dd, yyyy\"}",{"head":57},{},["Island",59],{"key":60,"params":61,"result":62},"FooterNav_JsYsxvLufb1W12aeknKZ89on0MD0bNDTiB5EYxyxmU",{"props":48},{"head":63},{},["Island",65],{"key":66,"params":67,"result":69},"FooterSocial_u16tCafBUeGMoDrdLfTINytP2JB5msc6iB3VDUutAoU",{"props":68},"{\"text-color\":\"gray\"}",{"head":70},{},{"count":72},199,{"count":74,"next":75,"previous":76,"results":77},17428,"https:\u002F\u002Fvulndb.pentest-tools.com\u002Fapi\u002Fvulns\u002F?page=2&page_size=1",null,[78],{"id":79,"detectable_with":80,"vuln_details":87,"vuln_id":105,"name":106,"published":107,"updated":76},29752,{"tool":81,"engine":84},{"id":82,"name":83},1,"Network Scanner",{"id":85,"name":86},2,"Nuclei",{"id":79,"epss_score":88,"epss_percentile":89,"in_cisa_catalog":9,"codename":76,"public_description":90,"description":76,"severity":91,"risk_description":92,"public_recommendation":93,"recommendation":76,"references":94,"cvssv3":99,"cve":100,"date":102,"software_type":76,"vendor":103,"product":104,"ptt_exploit_capabilities":76,"category":76},0.00697,0.51214,"Gravity Forms WordPress plugin version 3.1.0.4 and earlier contains an unauthenticated arbitrary file upload vulnerability caused by bypassing extension validation in hidden file upload fields. Unauthenticated attackers can upload any file type including PHP when a form has a File Upload field configured with Hidden visibility. The bypass works because the server-side extension validation is skipped for fields with gfield_visibility_hidden CSS class.","critical","The risk exists that a remote unauthenticated attacker can fully compromise the server to steal confidential information, install ransomware, or pivot to the internal network.","Update Gravity Forms to version 3.1.1 or later.",[95,96,97,98],"https:\u002F\u002Fgithub.com\u002Fmurrez\u002FCVE-2026-84434","https:\u002F\u002Fpatchstack.com\u002Fdatabase\u002Fwordpress\u002Fplugin\u002Fgravityforms\u002Fvulnerability\u002Fwordpress-gravity-forms-plugin-3-1-0-4-unauthenticated-arbitrary-file-upload-via-hidden-file-upload-field-vulnerability","https:\u002F\u002Fwww.wordfence.com\u002Fthreat-intel\u002Fvulnerabilities\u002Fid\u002F787e22a9-329b-4e71-bc2a-4f5524fc9356","https:\u002F\u002Fdocs.gravityforms.com\u002Fgravityforms-change-log\u002F",9.8,[101],"CVE-2026-84434","2026-09-19T00:00:00Z","rocketgenius","gravityforms","NETSCAN-NUCLEI-CVE-CVE-2026-84434","WordPress Gravity Forms Plugin \u003C=3.1.0.4 - Unauthenticated Arbitrary File Upload (CVE-2026-84434)","2026-09-21T00:00:00Z",{"count":74,"next":109,"previous":76,"results":110},"https:\u002F\u002Fvulndb.pentest-tools.com\u002Fapi\u002Fvulns\u002F?limit=25&page=2&search=",[111,119,143,167,191,212,235,250,272,292,303,324,348,371,393,406,420,441,464,482,503,525,553,580,606],{"id":79,"detectable_with":112,"vuln_details":115,"vuln_id":105,"name":118,"published":107,"updated":76},{"tool":113,"engine":114},{"id":82,"name":83},{"id":85,"name":86},{"id":79,"codename":76,"description":76,"severity":91,"risk_description":92,"public_description":90,"public_recommendation":93,"recommendation":76,"references":116,"cvssv3":99,"epss_score":88,"epss_percentile":89,"cve":117,"in_cisa_catalog":9,"date":102,"software_type":76,"vendor":103,"product":104,"ptt_exploit_capabilities":76},[95,96,97,98],[101],"WordPress Gravity Forms Plugin \u003C=3.1.0.4 - Unauthenticated Arbitrary File Upload",{"id":120,"detectable_with":121,"vuln_details":124,"vuln_id":141,"name":142,"published":102,"updated":76},29751,{"tool":122,"engine":123},{"id":82,"name":83},{"id":85,"name":86},{"id":120,"codename":76,"description":76,"severity":125,"risk_description":126,"public_description":127,"public_recommendation":128,"recommendation":76,"references":129,"cvssv3":134,"epss_score":135,"epss_percentile":136,"cve":137,"in_cisa_catalog":9,"date":139,"software_type":76,"vendor":140,"product":140,"ptt_exploit_capabilities":76},"medium","Attackers can execute JavaScript in victim's browser to steal authentication tokens, leading to account compromise.","Yamcs \u003C 5.9.4 contains a stored XSS caused by inadequate HTML escaping of attacker-controlled redirect_uri parameter in authorization template, letting attackers execute JavaScript to steal authentication data, exploit requires user to open crafted URL.","Update to version 5.9.4 or later.",[130,131,132,133],"https:\u002F\u002Fgithub.com\u002Fyamcs\u002Fyamcs\u002Fsecurity\u002Fadvisories\u002FGHSA-rxpg-wjf8-qv9c","https:\u002F\u002Fgithub.com\u002Fyamcs\u002Fyamcs\u002Fcommit\u002F4d47d5cdcf5d92c2c5bbbc19feada422923332e3","https:\u002F\u002Fgithub.com\u002Fyamcs\u002Fyamcs\u002Freleases\u002Ftag\u002Fyamcs-5.9.4","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-55549",6.5,0.00897,0.57565,[138],"CVE-2026-55549","2026-08-28T00:00:00Z","yamcs","NETSCAN-NUCLEI-CVE-CVE-2026-55549","Yamcs \u003C=5.8.6 - Cross-Site Scripting",{"id":144,"detectable_with":145,"vuln_details":148,"vuln_id":165,"name":166,"published":102,"updated":76},29750,{"tool":146,"engine":147},{"id":82,"name":83},{"id":85,"name":86},{"id":144,"codename":76,"description":76,"severity":91,"risk_description":149,"public_description":150,"public_recommendation":151,"recommendation":76,"references":152,"cvssv3":157,"epss_score":158,"epss_percentile":159,"cve":160,"in_cisa_catalog":9,"date":162,"software_type":76,"vendor":163,"product":164,"ptt_exploit_capabilities":76},"Remote unauthenticated attackers reach the full Argo CD tool surface with the operator's stored API token. Applications can be created pointing at attacker-controlled repositories and synced, which executes hostile manifests in the managed cluster under Argo CD's permissive default project.","argocd-mcp before 0.9.0 binds its MCP HTTP listener to all interfaces without requiring authentication. A remote unauthenticated attacker can initialize an MCP session, complete the handshake, and enumerate or invoke the full Argo CD tool surface using the operator's stored API token.","Upgrade to argocd-mcp 0.9.0 and set MCP_AUTH_TOKEN so inbound callers must present an Authorization bearer header. Keep --bind-address on 127.0.0.1 unless an external auth layer is in front of the listener, and do not use --allow-unauthenticated to restore a wide bind.",[153,154,155,156],"https:\u002F\u002Fgithub.com\u002Fargoproj-labs\u002Fmcp-for-argocd\u002Fsecurity\u002Fadvisories\u002FGHSA-rp45-5x3v-48mr","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-82456","https:\u002F\u002Fwww.vulncheck.com\u002Fadvisories\u002Fargocd-mcp-0.8.0-authentication-bypass-via-unauthenticated-http","https:\u002F\u002Fgithub.com\u002Fargoproj-labs\u002Fmcp-for-argocd\u002Freleases",10,0.01391,0.70707,[161],"CVE-2026-82456","2026-08-29T00:00:00Z","argoproj-labs","mcp-for-argocd","NETSCAN-NUCLEI-CVE-CVE-2026-82456","argocd-mcp 0.8.0 - Unauthenticated MCP Session and Tool Access",{"id":168,"detectable_with":169,"vuln_details":172,"vuln_id":188,"name":189,"published":190,"updated":76},29743,{"tool":170,"engine":171},{"id":82,"name":83},{"id":85,"name":86},{"id":168,"codename":76,"description":76,"severity":91,"risk_description":173,"public_description":174,"public_recommendation":175,"recommendation":76,"references":176,"cvssv3":157,"epss_score":181,"epss_percentile":182,"cve":183,"in_cisa_catalog":9,"date":185,"software_type":76,"vendor":186,"product":187,"ptt_exploit_capabilities":76},"Attackers can read and modify database content across all cleartext notebooks, potentially compromising data integrity and confidentiality.","SiYuan before v3.7.3 contains a SQL injection caused by direct concatenation of the keyword parameter in \u002Fapi\u002Ffiletree\u002FsearchDocs endpoint, letting attackers with publish RoleReader token or unauthenticated in publish mode read and modify database content.","Update to version 3.7.3 or later.",[177,178,179,180],"https:\u002F\u002Fgithub.com\u002Fsiyuan-note\u002Fsiyuan\u002Fsecurity\u002Fadvisories\u002FGHSA-33jq-p8c2-q3q4","https:\u002F\u002Fgithub.com\u002Fsiyuan-note\u002Fsiyuan\u002Freleases\u002Ftag\u002Fv3.7.3","https:\u002F\u002Fhub.docker.com\u002Fr\u002Fb3log\u002Fsiyuan\u002Ftags","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-69085",0.00875,0.56955,[184],"CVE-2026-69085","2026-08-03T00:00:00Z","b3log","siyuan","NETSCAN-NUCLEI-CVE-CVE-2026-69085","SiYuan \u003C=3.7.2 - SQL Injection","2026-09-18T00:00:00Z",{"id":192,"detectable_with":193,"vuln_details":196,"vuln_id":210,"name":211,"published":190,"updated":76},29748,{"tool":194,"engine":195},{"id":82,"name":83},{"id":85,"name":86},{"id":192,"codename":76,"description":76,"severity":197,"risk_description":198,"public_description":199,"public_recommendation":200,"recommendation":76,"references":201,"cvssv3":204,"epss_score":205,"epss_percentile":206,"cve":207,"in_cisa_catalog":9,"date":209,"software_type":76,"vendor":76,"product":76,"ptt_exploit_capabilities":76},"high","Unauthenticated users can access sensitive sales metrics, potentially exposing business-sensitive information.","Gutenberg Essential Blocks WordPress plugin \u003C 6.4.0 contains an information disclosure caused by unrestricted access to a public REST route exposing non-public WooCommerce sales metrics, letting unauthenticated users read product sales data.","Update to version 6.4.0 or later.",[202,203],"https:\u002F\u002Fwpscan.com\u002Fvulnerability\u002F0401a229-9630-49ab-ae4b-53360cf5d109\u002F","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-13153",7.5,0.00921,0.5825,[208],"CVE-2026-13153","2026-08-06T00:00:00Z","NETSCAN-NUCLEI-CVE-CVE-2026-13153","Essential Blocks \u003C 6.4.0 - Information Disclosure",{"id":213,"detectable_with":214,"vuln_details":217,"vuln_id":233,"name":234,"published":190,"updated":76},29747,{"tool":215,"engine":216},{"id":82,"name":83},{"id":85,"name":86},{"id":213,"codename":76,"description":76,"severity":197,"risk_description":218,"public_description":219,"public_recommendation":220,"recommendation":76,"references":221,"cvssv3":204,"epss_score":227,"epss_percentile":228,"cve":229,"in_cisa_catalog":231,"date":232,"software_type":76,"vendor":76,"product":76,"ptt_exploit_capabilities":76},"Unauthenticated attackers can access sensitive resources by obtaining internal tokens, potentially leading to information disclosure.","JFrog Artifactory contains an information disclosure caused by returning an internal anonymous-user token to unauthenticated callers when anonymous access is disabled, letting unauthenticated attackers access sensitive resources. The exploit requires anonymous access to be disabled.","Update to the latest version where this issue is fixed.",[222,223,224,225,226],"https:\u002F\u002Fdocs.jfrog.com\u002Freleases\u002Fdocs\u002Fjfrog-security-advisories","https:\u002F\u002Fwww.wiz.io\u002Fblog\u002Fartifactory-under-attack-in-the-wild-exploitation-of-cve-2026-42016-cve-2026-4201","https:\u002F\u002Fgithub.com\u002FBL0odz\u002FJFrog_CVE-2026-65615-ByGLM","https:\u002F\u002Fedrabb.fr\u002Fposts\u002Ffull-chain-preauth-rce-jfrog-artifactory\u002F","https:\u002F\u002Fwww.cisa.gov\u002Fknown-exploited-vulnerabilities-catalog?field_cve=CVE-2026-42018",0.11038,0.95772,[230],"CVE-2026-42018",true,"2026-08-12T00:00:00Z","NETSCAN-NUCLEI-CVE-CVE-2026-42018","JFrog Artifactory - Anonymous Token Disclosure via Trailing Slash Auth Bypass",{"id":236,"detectable_with":237,"vuln_details":240,"vuln_id":248,"name":249,"published":190,"updated":76},29746,{"tool":238,"engine":239},{"id":82,"name":83},{"id":85,"name":86},{"id":236,"codename":76,"description":76,"severity":197,"risk_description":241,"public_description":242,"public_recommendation":243,"recommendation":76,"references":244,"cvssv3":76,"epss_score":76,"epss_percentile":76,"cve":76,"in_cisa_catalog":9,"date":76,"software_type":76,"vendor":247,"product":247,"ptt_exploit_capabilities":76},"The risk exists that the data is unknowingly exposed to the internet, making it accessible to remote threat actors that can leverage it to attack the target, or the entire company, depending on the sensitivity of the data.","etcd's v3 API is reachable and authentication is disabled or not configured. With auth disabled, the v3 API grants full read and write access to every key in the store to anyone who can reach it.","Enable etcd client authentication and RBAC (`--client-cert-auth=true` plus `etcdctl auth enable`), and restrict network access to the etcd.",[245,246],"https:\u002F\u002Fetcd.io\u002Fdocs\u002Fv3.5\u002Fop-guide\u002Fauthentication\u002F","https:\u002F\u002Fetcd.io\u002Fdocs\u002Fv3.5\u002Fop-guide\u002Fsecurity\u002F","etcd","NETSCAN-NUCLEI-EXPOSURES-HTTP-ETCD-UNAUTHENTICATED-API-V3","etcd v3 Unauthenticated API",{"id":251,"detectable_with":252,"vuln_details":255,"vuln_id":270,"name":271,"published":190,"updated":76},29742,{"tool":253,"engine":254},{"id":82,"name":83},{"id":85,"name":86},{"id":251,"codename":76,"description":76,"severity":91,"risk_description":256,"public_description":257,"public_recommendation":258,"recommendation":76,"references":259,"cvssv3":99,"epss_score":264,"epss_percentile":265,"cve":266,"in_cisa_catalog":9,"date":268,"software_type":76,"vendor":269,"product":269,"ptt_exploit_capabilities":76},"The risk exists that a remote unauthenticated attacker could exploit this vulnerability to read sensitive information from arbitrary files located on the file system of the server.","TEN Framework 0.11.71 contains unauthenticated arbitrary file read and write vulnerabilities in the TMAN Designer file-content API endpoints, letting attackers read or write arbitrary files and execute code. The exploit requires no authentication.","Update to the latest version of TEN Framework.",[260,261,262,263],"https:\u002F\u002Fwww.vulncheck.com\u002Fadvisories\u002Ften-framework-0.11.71-unauthenticated-file-read-write-via-tman-designer","https:\u002F\u002Fgithub.com\u002FTEN-framework\u002Ften-framework\u002Fissues\u002F2187","https:\u002F\u002Fgithub.com\u002FTEN-framework\u002Ften-framework\u002Fblob\u002F0.11.71\u002Fcore\u002Fsrc\u002Ften_manager\u002Fsrc\u002Fdesigner\u002Ffile_content\u002Fmod.rs","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-85688",0.01469,0.72173,[267],"CVE-2026-85688","2026-09-04T00:00:00Z","ten-framework","NETSCAN-NUCLEI-CVE-CVE-2026-85688","TEN Framework - Arbitrary File Read & Write",{"id":273,"detectable_with":274,"vuln_details":277,"vuln_id":290,"name":291,"published":190,"updated":76},29745,{"tool":275,"engine":276},{"id":82,"name":83},{"id":85,"name":86},{"id":273,"codename":76,"description":76,"severity":91,"risk_description":92,"public_description":278,"public_recommendation":279,"recommendation":76,"references":280,"cvssv3":99,"epss_score":283,"epss_percentile":284,"cve":285,"in_cisa_catalog":231,"date":287,"software_type":76,"vendor":288,"product":289,"ptt_exploit_capabilities":76},"Ivanti Endpoint Manager Mobile contains a code injection vulnerability allowing unauthenticated attackers to execute arbitrary code remotely, exploit requires no authentication.","Update to the latest version of Ivanti Endpoint Manager Mobile.",[281,282],"https:\u002F\u002Fforums.ivanti.com\u002Fs\u002Farticle\u002FSecurity-Advisory-Ivanti-Endpoint-Manager-Mobile-EPMM","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-1340",0.98676,0.99923,[286],"CVE-2026-1340","2026-01-29T00:00:00Z","ivanti","endpoint_manager_mobile","NETSCAN-NUCLEI-CVE-CVE-2026-1340","Ivanti EPMM \u003C 12.8.0.0 - Remote Code Execution",{"id":293,"detectable_with":294,"vuln_details":297,"vuln_id":301,"name":302,"published":190,"updated":76},29749,{"tool":295,"engine":296},{"id":82,"name":83},{"id":85,"name":86},{"id":293,"codename":76,"description":76,"severity":197,"risk_description":241,"public_description":298,"public_recommendation":299,"recommendation":76,"references":300,"cvssv3":76,"epss_score":76,"epss_percentile":76,"cve":76,"in_cisa_catalog":9,"date":76,"software_type":76,"vendor":247,"product":247,"ptt_exploit_capabilities":76},"etcd's v2 API is reachable without authentication, exposing the \u002Fv2\u002Fmembers endpoint. This endpoint discloses the full cluster membership list, including each member's name, internal peer URLs, and client URLs, without requiring any credentials.","Disable the deprecated v2 API (etcd 3.4+ defaults to v2 disabled; confirm `--enable-v2=false`), enable client authentication and RBAC, and restrict network access to etcd's client",[245,246],"NETSCAN-NUCLEI-EXPOSURES-HTTP-ETCD-UNAUTHENTICATED-RAFT","etcd RAFT Unauthenticated API",{"id":304,"detectable_with":305,"vuln_details":308,"vuln_id":322,"name":323,"published":190,"updated":76},29740,{"tool":306,"engine":307},{"id":82,"name":83},{"id":85,"name":86},{"id":304,"codename":76,"description":76,"severity":91,"risk_description":309,"public_description":310,"public_recommendation":311,"recommendation":76,"references":312,"cvssv3":99,"epss_score":315,"epss_percentile":316,"cve":317,"in_cisa_catalog":9,"date":319,"software_type":76,"vendor":320,"product":321,"ptt_exploit_capabilities":76},"An unauthenticated attacker obtains a superuser access token, granting full control of the Langflow instance including flow creation and execution, which typically leads to remote code execution and access to connected credentials and data sources.","Langflow OSS with default AUTO_LOGIN exposes `\u002Fapi\u002Fv1\u002Fauto_login`, which returns a superuser access token to any unauthenticated request.","Disable AUTO_LOGIN by setting `LANGFLOW_AUTO_LOGIN=false`, configure strong superuser credentials, upgrade to a fixed Langflow release, and restrict network exposure of the management interface.",[313,314],"https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-9103","https:\u002F\u002Fgithub.com\u002Flangflow-ai\u002Flangflow",0.02828,0.85912,[318],"CVE-2026-9103","2026-07-17T00:00:00Z","langflow-ai","langflow","NETSCAN-NUCLEI-CVE-CVE-2026-9103","Langflow OSS - Superuser Token Issuance",{"id":325,"detectable_with":326,"vuln_details":329,"vuln_id":346,"name":347,"published":190,"updated":76},29744,{"tool":327,"engine":328},{"id":82,"name":83},{"id":85,"name":86},{"id":325,"codename":76,"description":76,"severity":91,"risk_description":92,"public_description":330,"public_recommendation":331,"recommendation":76,"references":332,"cvssv3":157,"epss_score":339,"epss_percentile":340,"cve":341,"in_cisa_catalog":231,"date":343,"software_type":76,"vendor":344,"product":345,"ptt_exploit_capabilities":76},"N-able N-central versions before 2026.3.1.14 are vulnerable to pre-authentication remote code execution via static code injection (CWE-96). An unauthenticated attacker with network access to the N-central management interface can execute arbitrary code on the server, potentially compromising every managed endpoint under the platform's control. Huntress confirmed active in-the-wild exploitation. N-able's hosted (NCOD) instances were automatically patched, on-premises deployments require manual upgrade to 2026.3.1.14. The N-central build version is exposed pre-authentication in the login page JavaScript object (ncentralVersion), enabling reliable version-based detection.","Upgrade N-central immediately to version 2026.3.1.14 (Hotfix 4) or later. Direct upgrade paths exist from builds 2025.4, 2026.1, 2026.2, 2026.3, and all 2026.3.1 hotfixes. Additionally restrict inbound access to N-central with IP allowlisting or VPN, audit N-central user accounts for unauthorized accounts (especially .invalid emails), and review appliance logs for evidence of pre-exploitation reconnaissance.",[333,334,335,336,337,338],"https:\u002F\u002Fme.n-able.com\u002Fs\u002Fsecurity-advisory\u002FaArVy00","https:\u002F\u002Fwww.huntress.com\u002Fblog\u002Fn-able-vulnerability-exploitation","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-86218","https:\u002F\u002Fwww.bleepingcomputer.com\u002Fnews\u002Fsecurity\u002Fn-able-patches-max-severity-n-central-flaw-amid-ongoing-attacks\u002F","https:\u002F\u002Fforkast.news\u002Fn-able-n-central-cvss-10-0-pre-auth-rce-marks-third-attack-wave-in-six-weeks\u002F","https:\u002F\u002Fcve.mitre.org\u002Fcgi-bin\u002Fcvename.cgi?name=CVE-2026-86218",0.07494,0.94295,[342],"CVE-2026-86218","2026-09-06T00:00:00Z","n-able","n-central","NETSCAN-NUCLEI-CVE-CVE-2026-86218","N-able N-central \u003C2026.3.1.14 - Pre-Authentication Remote Code Execution",{"id":349,"detectable_with":350,"vuln_details":353,"vuln_id":369,"name":370,"published":190,"updated":76},29741,{"tool":351,"engine":352},{"id":82,"name":83},{"id":85,"name":86},{"id":349,"codename":76,"description":76,"severity":91,"risk_description":92,"public_description":354,"public_recommendation":355,"recommendation":76,"references":356,"cvssv3":99,"epss_score":362,"epss_percentile":363,"cve":364,"in_cisa_catalog":9,"date":366,"software_type":76,"vendor":367,"product":368,"ptt_exploit_capabilities":76},"The org.h2.util.JdbcUtils.getConnection method of the H2 database takes as parameters the class name of the driver and URL of the database. An attacker may pass a JNDI driver name and a URL leading to a LDAP or RMI servers, causing remote code execution via the H2 web console (versions before 2.0.206 \u002F 1.4.198 with the console enabled).","Upgrade H2 database to version 2.0.206 or later, and disable the web console (spring.h2.console.enabled=false) or restrict access to it.",[357,358,359,360,361],"https:\u002F\u002Fjfrog.com\u002Fblog\u002Fthe-jndi-strikes-back-unauthenticated-rce-in-h2-database-console\u002F","https:\u002F\u002Fgithub.com\u002Fadvisories\u002FGHSA-h376-j262-vhq6","https:\u002F\u002Fgithub.com\u002Fh2database\u002Fh2database\u002Fcommit\u002Fb24aa46f48904ce64443f8f4353d70a2eed09037","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2021-42392","https:\u002F\u002Fgithub.com\u002Fvulhub\u002Fvulhub\u002Ftree\u002Fmaster\u002Fh2database\u002FCVE-2021-42392",0.83176,0.9967,[365],"CVE-2021-42392","2022-01-10T00:00:00Z","h2database","h2","NETSCAN-NUCLEI-CVE-CVE-2021-42392","H2 Database Console - JNDI Injection RCE",{"id":372,"detectable_with":373,"vuln_details":376,"vuln_id":390,"name":391,"published":392,"updated":76},29739,{"tool":374,"engine":375},{"id":82,"name":83},{"id":85,"name":86},{"id":372,"codename":76,"description":76,"severity":91,"risk_description":377,"public_description":378,"public_recommendation":379,"recommendation":76,"references":380,"cvssv3":99,"epss_score":384,"epss_percentile":385,"cve":386,"in_cisa_catalog":9,"date":388,"software_type":76,"vendor":389,"product":389,"ptt_exploit_capabilities":76},"An unauthenticated attacker gains a full administrator session on the WordPress site, allowing complete takeover including plugin\u002Ftheme editing, arbitrary PHP execution, and data theft.","The compromised Advanced Responsive Video Embedder WordPress plugin releases 10.8.7 and 10.8.8 accept a hardcoded token through the `_wplogin` parameter and establish an authenticated administrator session before normal authentication. A single unauthenticated GET request triggers the backdoor. This template only inspects the redirect and session-cookie response and does not perform any administrative action.","Immediately remove the Advanced Responsive Video Embedder plugin versions 10.8.7 and 10.8.8, reinstall a known-clean release, rotate all secrets and passwords, and audit for rogue administrator accounts and web shells created after the backdoor was published.",[381,382,383],"https:\u002F\u002Fwww.wordfence.com\u002Fblog\u002F2026\u002F07\u002Fwordfence-prism-detected-backdoored-wordpress-plugin-within-two-hours-of-it-being-introduced\u002F","https:\u002F\u002Fplugins.trac.wordpress.org\u002Fbrowser\u002Fadvanced-responsive-video-embedder\u002Ftags\u002F10.8.7\u002Fphp\u002Ffn-update-check.php","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-18072",0.03231,0.87701,[387],"CVE-2026-18072","2026-07-29T00:00:00Z","advanced-responsive-video-embedder","NETSCAN-NUCLEI-CVE-CVE-2026-18072","Advanced Responsive Video Embedder 10.8.7\u002F10.8.8 - Hardcoded Backdoor Authentication Bypass","2026-09-17T00:00:00Z",{"id":394,"detectable_with":395,"vuln_details":398,"vuln_id":403,"name":404,"published":405,"updated":76},29736,{"tool":396,"engine":397},{"id":82,"name":83},{"id":85,"name":86},{"id":394,"codename":76,"description":76,"severity":197,"risk_description":241,"public_description":399,"public_recommendation":400,"recommendation":76,"references":401,"cvssv3":76,"epss_score":76,"epss_percentile":76,"cve":76,"in_cisa_catalog":9,"date":76,"software_type":76,"vendor":320,"product":321,"ptt_exploit_capabilities":76},"Langflow instance is exposed without authentication, allowing unauthorized access to custom LLM flows and component node structures.","We suggest restricting access to the exposed resource.",[314,402],"https:\u002F\u002Fdocs.langflow.org\u002F","NETSCAN-NUCLEI-EXPOSURES-LANGFLOW-API-EXPOSURE","Langflow - Unauthenticated API Exposure","2026-09-16T00:00:00Z",{"id":407,"detectable_with":408,"vuln_details":411,"vuln_id":418,"name":419,"published":405,"updated":76},29737,{"tool":409,"engine":410},{"id":82,"name":83},{"id":85,"name":86},{"id":407,"codename":76,"description":76,"severity":197,"risk_description":241,"public_description":412,"public_recommendation":400,"recommendation":76,"references":413,"cvssv3":76,"epss_score":76,"epss_percentile":76,"cve":76,"in_cisa_catalog":9,"date":76,"software_type":76,"vendor":416,"product":417,"ptt_exploit_capabilities":76},"Flowise AI instance is exposed without authentication, allowing unauthorized access to visual LLM chatflows and integration configurations.",[414,415],"https:\u002F\u002Fgithub.com\u002FFlowiseAI\u002FFlowise","https:\u002F\u002Fdocs.flowiseai.com\u002F","flowiseai","flowise","NETSCAN-NUCLEI-EXPOSURES-FLOWISE-CHATFLOWS-EXPOSURE","Flowise AI - Unauthenticated Chatflows API Exposure",{"id":421,"detectable_with":422,"vuln_details":425,"vuln_id":439,"name":440,"published":405,"updated":76},29738,{"tool":423,"engine":424},{"id":82,"name":83},{"id":85,"name":86},{"id":421,"codename":76,"description":76,"severity":91,"risk_description":426,"public_description":427,"public_recommendation":428,"recommendation":76,"references":429,"cvssv3":99,"epss_score":433,"epss_percentile":434,"cve":435,"in_cisa_catalog":9,"date":437,"software_type":76,"vendor":438,"product":438,"ptt_exploit_capabilities":76},"An unauthenticated attacker can gain full admin access to the OpenCTI GraphQL API, including reading and modifying all threat intelligence data.","OpenCTI \u003C 6.9.13 allows authentication bypass by supplying a Bearer token set to the admin user's internal_id UUID instead of a valid JWT. The default admin internal_id (88ec0c6a-13ce-5e39-b486-354fe4a7084f) grants full admin access to the GraphQL API, effectively bypassing all authentication.","Upgrade OpenCTI to version 6.9.13 or later.",[430,431,432],"https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-27960","https:\u002F\u002Fwww.pruva.dev\u002Freproductions\u002FREPRO-2026-00314","https:\u002F\u002Fwww.pruva.dev\u002Freproductions\u002FREPRO-2026-00331",0.01995,0.79575,[436],"CVE-2026-27960","2026-05-05T00:00:00Z","opencti","NETSCAN-NUCLEI-CVE-CVE-2026-27960","OpenCTI \u003C 6.9.13 - Authentication Bypass via User Impersonation",{"id":442,"detectable_with":443,"vuln_details":446,"vuln_id":461,"name":462,"published":463,"updated":76},29713,{"tool":444,"engine":445},{"id":82,"name":83},{"id":85,"name":86},{"id":442,"codename":76,"description":76,"severity":91,"risk_description":447,"public_description":448,"public_recommendation":449,"recommendation":76,"references":450,"cvssv3":454,"epss_score":455,"epss_percentile":456,"cve":457,"in_cisa_catalog":9,"date":459,"software_type":76,"vendor":460,"product":460,"ptt_exploit_capabilities":76},"An unauthenticated network attacker can read unintended MongoDB data, including administrative usernames and password hashes when local authentication is enabled, by controlling DataTables query parameters.","cve-search versions 4.0 through 6.0.0 expose an unauthenticated DataTables endpoint that accepts attacker-controlled MongoDB collection, projection, filtering, and pagination parameters. This detector uses a harmless invalid projection field against the intended cves collection; version 6.0.1 rejects that field.","Upgrade cve-search to v6.0.1 or later.",[451,452,453],"https:\u002F\u002Fgithub.com\u002Fcve-search\u002Fcve-search\u002Fissues\u002F1217","https:\u002F\u002Fgithub.com\u002Fcve-search\u002Fcve-search\u002Fpull\u002F1218","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-59509",9.2,0.01426,0.71369,[458],"CVE-2026-59509","2026-07-05T00:00:00Z","cve-search","NETSCAN-NUCLEI-CVE-CVE-2026-59509","cve-search 4.0-6.0.0 - Unauthenticated NoSQL Injection","2026-09-15T00:00:00Z",{"id":465,"detectable_with":466,"vuln_details":469,"vuln_id":480,"name":481,"published":463,"updated":76},29718,{"tool":467,"engine":468},{"id":82,"name":83},{"id":85,"name":86},{"id":465,"codename":76,"description":76,"severity":91,"risk_description":92,"public_description":470,"public_recommendation":471,"recommendation":76,"references":472,"cvssv3":99,"epss_score":475,"epss_percentile":476,"cve":477,"in_cisa_catalog":9,"date":479,"software_type":76,"vendor":320,"product":321,"ptt_exploit_capabilities":76},"Langflow \u003C= 1.2.x exposes POST \u002Fapi\u002Fv1\u002Fvalidate\u002Fcode without any authentication. The endpoint calls validate_code() which exec()s user-supplied Python code. Default-argument expressions in Python execute at function-definition time, allowing arbitrary OS command execution without authentication.","Upgrade Langflow to a version that requires authentication on the validate\u002Fcode endpoint.",[473,474],"https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-0768","https:\u002F\u002Fwww.pruva.dev\u002Freproductions\u002FREPRO-2026-00342",0.07775,0.94466,[478],"CVE-2026-0768","2026-01-23T00:00:00Z","NETSCAN-NUCLEI-CVE-CVE-2026-0768","Langflow \u003C=1.2.x - Unauthenticated Remote Code Execution via validate_code",{"id":483,"detectable_with":484,"vuln_details":487,"vuln_id":501,"name":502,"published":463,"updated":76},29727,{"tool":485,"engine":486},{"id":82,"name":83},{"id":85,"name":86},{"id":483,"codename":76,"description":76,"severity":91,"risk_description":92,"public_description":488,"public_recommendation":489,"recommendation":76,"references":490,"cvssv3":99,"epss_score":494,"epss_percentile":495,"cve":496,"in_cisa_catalog":9,"date":498,"software_type":76,"vendor":499,"product":500,"ptt_exploit_capabilities":76},"ruflo MCP bridge (\u003C 3.16.3) in its default docker-compose deployment exposes POST \u002Fmcp with no authentication and binds to all interfaces (0.0.0.0:3001). The executeTool() function has no server-side deny list for dangerous tools, allowing an unauthenticated attacker to invoke tools\u002Fcall with ruflo__terminal_execute, which runs execSync(command) on attacker-supplied input. This yields arbitrary command execution as the node user (uid 1000) inside the bridge container. The blocklist (AUTOPILOT_BLOCKED_PATTERNS + isBlockedTool()) is enforced only in the autopilot SSE handler; POST \u002Fmcp and POST \u002Fmcp\u002F:group bypass it entirely.","Upgrade ruflo to version 3.16.3 or later which adds DANGEROUS_TOOLS gate in executeTool(), bearer auth middleware (MCP_AUTH_TOKEN), loopback bind by default (BIND_HOST=127.0.0.1), and MCP_ENABLE_TERMINAL opt-in. As interim mitigation, firewall port 3001 and set MCP_AUTH_TOKEN in docker-compose.yml.",[491,492,493],"https:\u002F\u002Fgithub.com\u002Fruvnet\u002Fruflo\u002Fsecurity\u002Fadvisories\u002FGHSA-c4hm-4h84-2cf3","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-59726","https:\u002F\u002Fwww.pruva.dev\u002Freproductions\u002FREPRO-2026-00315",0.16428,0.96891,[497],"CVE-2026-59726","2026-07-09T00:00:00Z","ruvnet","ruflo","NETSCAN-NUCLEI-CVE-CVE-2026-59726","ruflo MCP Bridge - Unauthenticated RCE via terminal_execute",{"id":504,"detectable_with":505,"vuln_details":508,"vuln_id":523,"name":524,"published":463,"updated":76},29731,{"tool":506,"engine":507},{"id":82,"name":83},{"id":85,"name":86},{"id":504,"codename":76,"description":76,"severity":125,"risk_description":509,"public_description":510,"public_recommendation":511,"recommendation":76,"references":512,"cvssv3":516,"epss_score":517,"epss_percentile":518,"cve":519,"in_cisa_catalog":9,"date":521,"software_type":76,"vendor":522,"product":522,"ptt_exploit_capabilities":76},"An unauthenticated visitor can retrieve the contents of a hidden post revision that moderators intended to conceal from public viewers.","Discourse versions before 2026.1.2, 2026.2.1, and 2026.3.0-latest.1 contain an authorization bypass in PostsController#display_post. The controller calls post.revert_to(params[:version]) directly whenever a version query parameter is present, without checking whether the corresponding PostRevision is hidden or whether the caller has permission to view edit history. By requesting a post at its publicly known version number via GET \u002Fposts\u002F:id.json?version=\u003Cpublic_version>, the next PostRevision's stored modifications are applied unconditionally. If staff have hidden that revision, its pre-edit content is returned to an unauthenticated caller. On patched installs the same request is rejected with 403 because guardian.ensure_can_see!(post_revision) is evaluated first.","Upgrade Discourse to 2026.1.2, 2026.2.1, 2026.3.0-latest.1, or later.",[513,514,515],"https:\u002F\u002Fgithub.com\u002Fdiscourse\u002Fdiscourse\u002Fsecurity\u002Fadvisories\u002FGHSA-fq69-f929-wp96","https:\u002F\u002Fgithub.com\u002Fdiscourse\u002Fdiscourse\u002Fcommit\u002F8510fde30eb0d7f2dee822a95f6cf43b9ac943d0","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-27454",5.3,0.00893,0.57428,[520],"CVE-2026-27454","2026-03-19T00:00:00Z","discourse","NETSCAN-NUCLEI-CVE-CVE-2026-27454","Discourse \u003C=2026.2.0 - Hidden Post Revision Disclosure via revert_to Authorization Bypass",{"id":526,"detectable_with":527,"vuln_details":531,"vuln_id":551,"name":552,"published":463,"updated":463},29733,{"tool":528,"engine":529},{"id":82,"name":83},{"id":82,"name":530},"Sniper",{"id":526,"codename":532,"description":533,"severity":91,"risk_description":92,"public_description":534,"public_recommendation":535,"recommendation":536,"references":537,"cvssv3":157,"epss_score":542,"epss_percentile":543,"cve":544,"in_cisa_catalog":9,"date":388,"software_type":546,"vendor":547,"product":548,"ptt_exploit_capabilities":549},"KindaRails2Shell","We found that the target Ruby on Rails server is vulnerable to CVE-2026-66066 (GHSA-xr9x-r78c-5hrm, nicknamed \"KindaRails2Shell\"), a type confusion vulnerability (CWE-1188) in Active Storage's libvips-based variant processing. By default, Active Storage lets libvips process untrusted, unfuzzed file formats; an attacker can upload a crafted MATLAB 5.0 \u002F HDF5 polyglot blob whose external-link dataset causes libvips to leak an arbitrary server-side file (e.g. \u002Fproc\u002Fself\u002Fenviron) back through the rendered image's pixel data. By leaking SECRET_KEY_BASE this way, an unauthenticated attacker can forge a signed Active Storage variation token carrying an instance_eval payload that Rails evaluates on deserialization, resulting in unauthenticated remote code execution in the context of the Rails process. Exploitation does not require user interaction.\nWe have detected this by uploading a crafted polyglot blob to leak SECRET_KEY_BASE from the target, then forging a variation token to execute the id command and retrieving its output back through the same file-read primitive.","Ruby on Rails Active Storage, when using the default libvips image variant processor, is vulnerable to CVE-2026-66066 (\"KindaRails2Shell\"), a type confusion vulnerability that lets an unauthenticated attacker read arbitrary files from the server and, by leaking the application's SECRET_KEY_BASE, forge a signed request that leads to remote code execution.","Update Ruby on Rails Active Storage to version 7.2.3.2, 8.0.5.1, 8.1.3.1 or later, and rotate SECRET_KEY_BASE and other application credentials.","We recommend updating the activestorage gem to version 7.2.3.2, 8.0.5.1, 8.1.3.1 or later, ensuring libvips is upgraded to version 8.13 or later, and rotating SECRET_KEY_BASE, the Rails master key, and any other credentials the application process could read, since they may already have been exposed.",[538,539,540,541],"https:\u002F\u002Fgithub.com\u002Frails\u002Frails\u002Fsecurity\u002Fadvisories\u002FGHSA-xr9x-r78c-5hrm","https:\u002F\u002Fdiscuss.rubyonrails.org\u002Ft\u002Fcve-2026-66066-possible-arbitrary-file-read-and-remote-code-execution-in-active-storage-variant-processing\u002F91432","https:\u002F\u002Fwww.openwall.com\u002Flists\u002Foss-security\u002F2026\u002F07\u002F29\u002F9","https:\u002F\u002Fadvisories.gitlab.com\u002Fgem\u002Factivestorage\u002FCVE-2026-66066\u002F",0.27861,0.98058,[545],"CVE-2026-66066","Shared library","Rails","Active Storage",[550],"RCE","NETSCAN-SNIPER-CVE-2026-66066","Ruby on Rails Active Storage - Remote Code Execution",{"id":554,"detectable_with":555,"vuln_details":558,"vuln_id":578,"name":579,"published":463,"updated":463},29735,{"tool":556,"engine":557},{"id":82,"name":83},{"id":82,"name":530},{"id":554,"codename":76,"description":559,"severity":91,"risk_description":560,"public_description":561,"public_recommendation":562,"recommendation":563,"references":564,"cvssv3":99,"epss_score":569,"epss_percentile":570,"cve":571,"in_cisa_catalog":231,"date":573,"software_type":574,"vendor":575,"product":576,"ptt_exploit_capabilities":577},"We found that the target server is running JetBrains TeamCity On-Premises in a version older than 2026.1.3 or 2025.11.7, which is vulnerable to unauthenticated remote code execution through the agent polling protocol. The endpoints under \u002Fapp\u002Fagents\u002Fv1\u002F are reachable without authentication and deserialize attacker-supplied XML using XStream. The root cause is that XStreamHolder.setupSecurityIfNeeded() applies its allowlist without first clearing XStream's default type permissions with NoTypePermission.NONE, so the permissive defaults covering the Map and Throwable hierarchies remain in effect and the allowlist is additive rather than exclusive. After registering an agent session on \u002Fapp\u002Fagents\u002Fv1\u002Fregister, an attacker can post a crafted object graph to \u002Fapp\u002Fagents\u002Fv1\u002Fcommands\u002Ferror that chains a TeamCity exception class, a FreeMarker bean wrapper and a TiedMapEntry to reach BasicDataSource.getConnection(). Opening that connection runs attacker-controlled init SQL against an in-memory HSQLDB, whose SCRIPT statement writes a polyglot SQL\u002FJSP file into the TeamCity web root, which the server then compiles and executes on the next request.","The risk exists that a remote unauthenticated attacker can fully compromise the server to steal confidential information, install ransomware, or pivot to the internal network. Because TeamCity is a build server, code execution also exposes stored CI\u002FCD credentials, signing keys and source code, which can be abused to tamper with build artifacts and reach downstream production systems. The vulnerability is rated critical, requires no authentication, has public exploit code available and is confirmed to be exploited in the wild.","JetBrains TeamCity On-Premises versions before 2026.1.3 and 2025.11.7 are vulnerable to unauthenticated remote code execution via the agent polling protocol. The agent endpoints are exposed without authentication and deserialize untrusted XML with XStream using an incorrectly configured allowlist, which leaves the library's permissive default type permissions in place. An attacker who can reach the TeamCity server over the network can register an agent session and submit a crafted object graph that writes an executable file into the server's web root and runs arbitrary code, without any credentials or user interaction. This vulnerability is listed in the CISA Known Exploited Vulnerabilities catalog and has been observed being exploited in the wild.","Update JetBrains TeamCity On-Premises to version 2026.1.3 or 2025.11.7 or later, or apply the vendor-provided security patch plugin.","We recommend upgrading JetBrains TeamCity On-Premises to version 2026.1.3 or 2025.11.7 or later. If an immediate upgrade is not possible, JetBrains provides a security patch plugin for TeamCity 2017.1 and newer that addresses this issue, and access to the server and its agent endpoints should be restricted at the network boundary in the meantime. Because this vulnerability is known to be exploited in the wild, we also recommend reviewing the server for unexpected files in the web root, unknown agent registrations, and rotating any credentials stored in TeamCity.",[565,566,567,568],"https:\u002F\u002Fblog.jetbrains.com\u002Fteamcity\u002F2026\u002F07\u002Fcve-2026-63077\u002F","https:\u002F\u002Fwww.rapid7.com\u002Fblog\u002Fpost\u002Fetr-cve-2026-63077-critical-unauthenticated-remote-code-execution-in-jetbrains-teamcity\u002F","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-63077","https:\u002F\u002Fwww.cisa.gov\u002Fknown-exploited-vulnerabilities-catalog?field_cve=CVE-2026-63077",0.86518,0.99734,[572],"CVE-2026-63077","2026-07-27T00:00:00Z","Continuous Integration Server","JetBrains","TeamCity",[550],"NETSCAN-SNIPER-CVE-2026-63077","JetBrains TeamCity - Remote Code Execution",{"id":581,"detectable_with":582,"vuln_details":585,"vuln_id":604,"name":605,"published":463,"updated":76},29714,{"tool":583,"engine":584},{"id":82,"name":83},{"id":85,"name":86},{"id":581,"codename":76,"description":76,"severity":91,"risk_description":586,"public_description":587,"public_recommendation":588,"recommendation":76,"references":589,"cvssv3":596,"epss_score":597,"epss_percentile":598,"cve":599,"in_cisa_catalog":9,"date":601,"software_type":76,"vendor":602,"product":603,"ptt_exploit_capabilities":76},"Unauthenticated attackers can traverse the Plugin Daemon's internal REST API, leaking system metadata (version hash, platform, pool capacity). Any internal Plugin Daemon endpoint is reachable, meaning any new endpoint becomes instantly exploitable from the public internet without credentials.","Dify version 1.14.1 and prior are affected by an unauthenticated path traversal in the Plugin Daemon icon proxy endpoint. The \u002Fconsole\u002Fapi\u002Fworkspaces\u002Fcurrent\u002Fplugin\u002Ficon endpoint requires no authentication and passes the filename query parameter unsanitized into the internal Plugin Daemon REST API URL. Using ..\u002F dot-sequence traversal an attacker escapes the authorized plugin\u002F{tenant_id}\u002Fasset\u002F namespace and reaches arbitrary internal Plugin Daemon endpoints. The \u002Fhealth\u002Fcheck endpoint is always available and returns Plugin Daemon version, build time and pool status confirming exploitation.","Upgrade to Dify 1.15.0 or later. The fix in api\u002Fcore\u002Fplugin\u002Fimpl\u002Fbase.py (BasePluginClient._prepare_request) URL-decodes the path and raises ValueError on any segment containing .. or %2e%2e, preventing path traversal sequences from being forwarded to the Plugin Daemon.",[590,591,592,593,594,595],"https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-41948","https:\u002F\u002Fwww.zafran.io\u002Fresources\u002Fdifytap-zafran-discovers-how-attackers-can-silently-wiretap-ai-data-across-tenants-on-a-platform-powering-1m-apps","https:\u002F\u002Fhuntr.com\u002Fbounties\u002F35b7ad59-e35d-443f-bf77-387bfb932ec0","https:\u002F\u002Fgithub.com\u002Flanggenius\u002Fdify\u002Fpull\u002F35796","https:\u002F\u002Fosv.dev\u002Fvulnerability\u002FCVE-2026-41948","https:\u002F\u002Fwww.vulncheck.com\u002Fadvisories\u002Fdify-path-traversal-via-plugin-daemon-internal-api-access",9.4,0.14453,0.9652,[600],"CVE-2026-41948","2026-05-18T00:00:00Z","langgenius","dify","NETSCAN-NUCLEI-CVE-CVE-2026-41948","Dify \u003C=1.14.1 - Unauthenticated Plugin Daemon Path Traversal",{"id":607,"detectable_with":608,"vuln_details":611,"vuln_id":625,"name":626,"published":463,"updated":76},29719,{"tool":609,"engine":610},{"id":82,"name":83},{"id":85,"name":86},{"id":607,"codename":76,"description":76,"severity":91,"risk_description":92,"public_description":612,"public_recommendation":613,"recommendation":76,"references":614,"cvssv3":618,"epss_score":619,"epss_percentile":620,"cve":621,"in_cisa_catalog":9,"date":623,"software_type":76,"vendor":624,"product":624,"ptt_exploit_capabilities":76},"OmniRoute \u003C= 3.8.49 contains a remote code execution caused by insufficient validation of interpreter arguments in the POST \u002Fapi\u002Facp\u002Fagents endpoint, letting remote attackers execute arbitrary code, exploit requires anonymous access when requireLogin is false or management session\u002FAPI key when true.","Update to the latest version once a fix is available.",[615,616,617],"https:\u002F\u002Fgithub.com\u002Fdiegosouzapw\u002FOmniRoute\u002Fsecurity\u002Fadvisories\u002FGHSA-hf57-cqmx-p4gr","https:\u002F\u002Fgithub.com\u002Fdiegosouzapw\u002FOmniRoute\u002Fpull\u002F11028","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-88062",9.5,0.00943,0.58962,[622],"CVE-2026-88062","2026-09-10T00:00:00Z","omniroute","NETSCAN-NUCLEI-CVE-CVE-2026-88062","OmniRoute \u003C 3.8.49 - Unauthenticated RCE"]