[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"all-banners":3,"SkipToContent_34xgpJIRRkpiT6ls6jE4NHf7VpvQCQBEwi69exi4oT0":76,"FooterNav_JsYsxvLufb1W12aeknKZ89on0MD0bNDTiB5EYxyxmU":83,"FormattedDate_YGZoki4KbemRpkMkk2LxWIughCHzKqWyXU32hDxuo":89,"FooterSocial_u16tCafBUeGMoDrdLfTINytP2JB5msc6iB3VDUutAoU":96,"$f17q7jdn7tll3p":103,"$f2r4b9phgo6bha":134,"finding-templates-{\"q\":\"\",\"page\":1}":136},[4,15,23,28,37,43,49,55,61,66],{"title":5,"slug":6,"text":7,"link":8,"external":9,"targets":10,"cta":12,"variant":13,"campaign_id":14},"wp2shell (Vuln DB homepage)","wp2shell-vuln-db","Emergency CVE response: detection & exploitation now available for *wp2shell*, the critical WP RCE chain","https:\u002F\u002Fpentest-tools.com\u002Fvulnerabilities-exploits\u002Fwordpress-core-69-701-pre-auth-blind-sql-injection-batch-route-confusion_29451",false,[11],"\u002Fvulnerabilities-exploits\u002F","See CVE details","secondary","wp2shell",{"title":16,"slug":17,"text":18,"link":19,"external":9,"targets":20,"cta":22,"variant":13,"campaign_id":14},"wp2shell (CVE page - exploitation)","wp2shell-cve-page-exploit","Validate wp2shell exposure & mitigation! Detect with any plan. Exploit with Pentest Suite.","https:\u002F\u002Fpentest-tools.com\u002Fpricing",[21],"\u002Fvulnerabilities-exploits\u002Fwp2shell-wordpress-core-690-694-and-700-701-pre-auth-batch-route-confusion-leading-to-sql-injection_29452","Explore plans",{"title":24,"slug":25,"text":18,"link":19,"external":9,"targets":26,"cta":22,"variant":13,"campaign_id":14},"wp2shell (CVE page - detection)","wp2shell-cve-page",[27],"\u002Fvulnerabilities-exploits\u002Fwordpress-core-69-701-pre-auth-blind-sql-injection-batch-route-confusion_29451",{"title":29,"slug":30,"text":31,"link":32,"external":9,"targets":33,"cta":35,"variant":13,"campaign_id":36},"Compliance - Page Launch - Network Scanner","compliance-pages-launch-network-scanner","Scheduled scans are the spine of every compliance framework. Are you audit-ready?","https:\u002F\u002Fpentest-tools.com\u002Fusage\u002Fcompliance",[34],"\u002Fnetwork-vulnerability-scanning\u002Fnetwork-security-scanner-online","Get compliance evidence","compliance-pages-launch",{"title":38,"slug":39,"text":40,"link":32,"external":9,"targets":41,"cta":35,"variant":13,"campaign_id":36},"Compliance - Page Launch - Website Scanner","compliance-pages-launch-website-scanner","Authenticated web-app scans show up in SOC 2, NIS2, and CRA Annex I. See why this is crucial for the business.",[42],"\u002Fwebsite-vulnerability-scanning\u002Fwebsite-scanner",{"title":44,"slug":45,"text":46,"link":32,"external":9,"targets":47,"cta":35,"variant":13,"campaign_id":36},"Compliance - Page Launch - Advanced Pentest Reporting","compliance-pages-launch-reporting","Editable DOCX. Immutable PDF. JSON for the GRC tool. See why these formats are on every auditor's checklist.",[48],"\u002Ffeatures\u002Fpentest-reporting",{"title":50,"slug":51,"text":52,"link":32,"external":9,"targets":53,"cta":35,"variant":13,"campaign_id":36},"Compliance - Page Launch - Integrations","compliance-pages-launch-integrations","Vanta, Jira, webhooks - they all route back to DORA, NIS2, SOC 2, ISO 27001, CRA. See why this is crucial for the business.",[54],"\u002Ffeatures\u002Fintegrations",{"title":56,"slug":57,"text":58,"link":32,"external":9,"targets":59,"cta":35,"variant":13,"campaign_id":36},"Compliance - Page Launch - Sniper","compliance-pages-launch-sniper","Five compliance framework pages now reference Sniper as the source of validated exploitability evidence. See them all.",[60],"\u002Fexploit-helpers\u002Fsniper",{"title":62,"slug":36,"text":63,"link":32,"external":9,"targets":64,"cta":35,"variant":13,"campaign_id":36},"Compliance - Page Launch - Homepage","Turn confirmed vulnerabilities into evidence your auditor accepts. Testing requirements for DORA, NIS2, SOC 2, ISO 27001, and CRA.",[65],"\u002F",{"title":67,"slug":68,"text":69,"link":70,"external":71,"targets":72,"cta":75,"variant":13,"campaign_id":68},"Office Hours #11 - Compliance cycle survey","office-hours-11","[Live Office Hours, Wed Sept 9] Continuous compliance evidence: from automated tools or tired humans?","https:\u002F\u002Fzoom.us\u002Fwebinar\u002Fregister\u002F5117815316917\u002FWN_FLMs2-vyQbCTB67guMJH-Q",true,[65,73,74],"\u002Finsights\u002Fcompliance-cycles-survey","\u002Finsights","Save your spot",["Island",77],{"key":78,"params":79,"result":81},"SkipToContent_34xgpJIRRkpiT6ls6jE4NHf7VpvQCQBEwi69exi4oT0",{"props":80},"{}",{"head":82},{},["Island",84],{"key":85,"params":86,"result":87},"FooterNav_JsYsxvLufb1W12aeknKZ89on0MD0bNDTiB5EYxyxmU",{"props":80},{"head":88},{},["Island",90],{"key":91,"params":92,"result":94},"FormattedDate_YGZoki4KbemRpkMkk2LxWIughCHzKqWyXU32hDxuo",{"props":93},"{\"date\":1778569448,\"format\":\"MMMM dd, yyyy\"}",{"head":95},{},["Island",97],{"key":98,"params":99,"result":101},"FooterSocial_u16tCafBUeGMoDrdLfTINytP2JB5msc6iB3VDUutAoU",{"props":100},"{\"text-color\":\"gray\"}",{"head":102},{},{"count":104,"next":105,"previous":106,"results":107},17355,"https:\u002F\u002Fvulndb.pentest-tools.com\u002Fapi\u002Fvulns\u002F?page=2&page_size=1",null,[108],{"id":109,"detectable_with":110,"vuln_details":117,"vuln_id":131,"name":132,"published":133,"updated":106},29675,{"tool":111,"engine":114},{"id":112,"name":113},1,"Network Scanner",{"id":115,"name":116},2,"Nuclei",{"id":109,"epss_score":118,"epss_percentile":119,"in_cisa_catalog":71,"codename":106,"public_description":120,"description":106,"severity":121,"risk_description":122,"public_recommendation":123,"recommendation":106,"references":124,"cvssv3":127,"cve":128,"date":130,"software_type":106,"vendor":106,"product":106,"ptt_exploit_capabilities":106,"category":106},0.11845,0.95804,"Sangoma Switchvox before version 8.4.0.2 contains an unauthenticated SQL injection vulnerability in the \u002Fpa endpoint (PhoneAppsHandler.pm). The PhoneIP field extracted from an XML POST body is concatenated directly into an unparameterized PostgreSQL query that runs as a database superuser. An attacker can break out of the single-quoted SQL string context and leverage PostgreSQL COPY TO PROGRAM to execute arbitrary operating system commands without authentication.","critical","The risk exists that a remote unauthenticated attacker can fully compromise the server to steal confidential information, install ransomware, or pivot to the internal network.","Upgrade Sangoma Switchvox to version 8.4.0.2 or later which parameterizes the SQL query and validates the PhoneIP input.",[125,126],"https:\u002F\u002Fhorizon3.ai\u002Fattack-research\u002Fdisclosures\u002Fcve-2026-9586-sangoma-switchvox-rce\u002F","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-9586",9.8,[129],"CVE-2026-9586","2026-07-17T00:00:00Z","NETSCAN-NUCLEI-CVE-CVE-2026-9586","Sangoma Switchvox \u003C 8.4.0.2 - Unauthenticated SQL Injection (CVE-2026-9586)","2026-09-02T00:00:00Z",{"count":135},195,{"count":104,"next":137,"previous":106,"results":138},"https:\u002F\u002Fvulndb.pentest-tools.com\u002Fapi\u002Fvulns\u002F?limit=25&page=2&search=",[139,158,166,183,201,220,243,264,283,301,322,336,348,370,390,410,422,434,455,468,488,500,525,548,570],{"id":140,"detectable_with":141,"vuln_details":144,"vuln_id":156,"name":157,"published":133,"updated":106},29679,{"tool":142,"engine":143},{"id":112,"name":113},{"id":115,"name":116},{"id":140,"codename":106,"description":106,"severity":121,"risk_description":145,"public_description":146,"public_recommendation":147,"recommendation":106,"references":148,"cvssv3":127,"epss_score":151,"epss_percentile":152,"cve":153,"in_cisa_catalog":71,"date":155,"software_type":106,"vendor":106,"product":106,"ptt_exploit_capabilities":106},"Unauthenticated attackers can gain administrative privileges, leading to full system control.","JFrog Artifactory contains an authentication weakness that, under default configuration, may allow an unauthenticated attacker with network access to obtain administrative privileges.","Update to the latest version and ensure secure configuration.",[149,150],"https:\u002F\u002Fjfrog.com\u002Fhelp\u002Fr\u002Fjfrog-release-information\u002Fartifactory-security-fixes","https:\u002F\u002Fwww.pruva.dev\u002Freproductions\u002FREPRO-2026-00341",0.07666,0.94175,[154],"CVE-2026-82329","2026-08-28T00:00:00Z","NETSCAN-NUCLEI-CVE-CVE-2026-82329","JFrog Artifactory Access Blank Join Key Authentication Bypass",{"id":109,"detectable_with":159,"vuln_details":162,"vuln_id":131,"name":165,"published":133,"updated":106},{"tool":160,"engine":161},{"id":112,"name":113},{"id":115,"name":116},{"id":109,"codename":106,"description":106,"severity":121,"risk_description":122,"public_description":120,"public_recommendation":123,"recommendation":106,"references":163,"cvssv3":127,"epss_score":118,"epss_percentile":119,"cve":164,"in_cisa_catalog":71,"date":130,"software_type":106,"vendor":106,"product":106,"ptt_exploit_capabilities":106},[125,126],[129],"Sangoma Switchvox \u003C 8.4.0.2 - Unauthenticated SQL Injection",{"id":167,"detectable_with":168,"vuln_details":171,"vuln_id":181,"name":182,"published":133,"updated":106},29678,{"tool":169,"engine":170},{"id":112,"name":113},{"id":115,"name":116},{"id":167,"codename":106,"description":106,"severity":172,"risk_description":173,"public_description":174,"public_recommendation":175,"recommendation":106,"references":176,"cvssv3":178,"epss_score":106,"epss_percentile":106,"cve":179,"in_cisa_catalog":9,"date":106,"software_type":106,"vendor":106,"product":106,"ptt_exploit_capabilities":106},"high","An unauthenticated attacker can craft a malicious URL that executes arbitrar JavaScript when opened by a victim. If a privileged GeoNetwork user such as an administrator visits the URL, the attacker may perform actions within the security context of that user.","GeoNetwork versions 4.4.5 through 4.4.11 are vulnerable to reflected cross-site scripting (XSS) in the public unauthenticated catalog search functionality. The uiconfig query parameter of the catalog.search endpoint is reflected into a JavaScript context without sufficient sanitization, allowing arbitrary JavaScript execution in a victim's browser.","Upgrade GeoNetwork to version 4.4.12 or later.",[177],"https:\u002F\u002Fgithub.com\u002Fgeonetwork\u002Fcore-geonetwork\u002Fsecurity\u002Fadvisories\u002FGHSA-5pq9-ppfw-p83j",8.2,[180],"CVE-2026-57582","NETSCAN-NUCLEI-CVE-CVE-2026-57582","GeoNetwork - Reflected Cross-Site Scripting",{"id":184,"detectable_with":185,"vuln_details":188,"vuln_id":199,"name":200,"published":133,"updated":106},29677,{"tool":186,"engine":187},{"id":112,"name":113},{"id":115,"name":116},{"id":184,"codename":106,"description":106,"severity":121,"risk_description":122,"public_description":189,"public_recommendation":190,"recommendation":106,"references":191,"cvssv3":127,"epss_score":194,"epss_percentile":195,"cve":196,"in_cisa_catalog":9,"date":198,"software_type":106,"vendor":106,"product":106,"ptt_exploit_capabilities":106},"Tutor LMS WordPress plugin \u003C 4.0.6 contains a template injection caused by insufficient prevention of request data overwriting internal variables during template rendering, letting unauthenticated attackers invoke arbitrary zero-argument PHP functions and receive their output.","Update to version 4.0.6 or later.",[192,193],"https:\u002F\u002Fwpscan.com\u002Fvulnerability\u002Fda7fb4c7-6d07-4c96-bde2-95bca1797d56\u002F","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-19092",0.01498,0.72502,[197],"CVE-2026-19092","2026-08-27T00:00:00Z","NETSCAN-NUCLEI-CVE-CVE-2026-19092","Tutor LMS \u003C 4.0.6 - Unauthenticated Arbitrary PHP Function Invocation",{"id":202,"detectable_with":203,"vuln_details":206,"vuln_id":218,"name":219,"published":133,"updated":106},29676,{"tool":204,"engine":205},{"id":112,"name":113},{"id":115,"name":116},{"id":202,"codename":106,"description":106,"severity":121,"risk_description":122,"public_description":207,"public_recommendation":208,"recommendation":106,"references":209,"cvssv3":127,"epss_score":213,"epss_percentile":214,"cve":215,"in_cisa_catalog":9,"date":217,"software_type":106,"vendor":106,"product":106,"ptt_exploit_capabilities":106},"mJobtime v15.7.2 contains a sql injection caused by crafted POST request to \u002FDefault.aspx\u002Fupdate_profile_Server, letting unauthenticated attackers execute arbitrary SQL statements remotely, exploit requires no special privileges.","Update to the latest version of mJobtime.",[210,211,212],"https:\u002F\u002Flabs.infoguard.ch\u002Fadvisories\u002Fcve-2025-51682_cve-2025-51683_time_management_softare_sqli-rce\u002F","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2025-51683","https:\u002F\u002Fgithub.com\u002Fadvisories\u002FGHSA-gp72-w5fg-q33m",0.018,0.77016,[216],"CVE-2025-51683","2025-12-01T00:00:00Z","NETSCAN-NUCLEI-CVE-CVE-2025-51683","mJobTime \u003C= 15.7.2 - Unauthenticated Blind SQL Injection to RCE",{"id":221,"detectable_with":222,"vuln_details":225,"vuln_id":240,"name":241,"published":242,"updated":106},29671,{"tool":223,"engine":224},{"id":112,"name":113},{"id":115,"name":116},{"id":221,"codename":106,"description":106,"severity":226,"risk_description":227,"public_description":228,"public_recommendation":229,"recommendation":106,"references":230,"cvssv3":234,"epss_score":235,"epss_percentile":236,"cve":237,"in_cisa_catalog":9,"date":239,"software_type":106,"vendor":106,"product":106,"ptt_exploit_capabilities":106},"medium","Successful exploitation allows an attacker to run arbitrary JavaScript in the context of the victim's browser (session hijacking, data theft, or account takeover) if the victim visits a crafted Swagger UI documentation URL within mailcow-dockerized affected versions.","Mailcow-dockerized before 2022-09a uses a vulnerable version of Swagger UI (before 4.11.1) that is affected by a DOM-based Cross-Site Scripting (XSS) vulnerability. When a user accesses the Swagger documentation with a crafted configUrl or url parameter containing JavaScript payloads, arbitrary code execution can occur in the user's browser. This allows attackers to steal cookies, session data, or execute actions on behalf of the victim by enticing them to open a malicious Swagger UI link.","Upgrade mailcow-dockerized to at least 2022-09a, which updates Swagger UI to version 4.11.1 or later. Do not expose internal Swagger UI endpoints publicly.",[231,232,233],"https:\u002F\u002Fgithub.com\u002Fmailcow\u002Fmailcow-dockerized\u002Fsecurity\u002Fadvisories\u002FGHSA-99r2-q6fj-6w47","https:\u002F\u002Fgithub.com\u002Fswagger-api\u002Fswagger-ui\u002Fissues\u002F8322","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2022-39258",6.1,0.01524,0.72937,[238],"CVE-2022-39258","2022-09-27T00:00:00Z","NETSCAN-NUCLEI-CVE-CVE-2022-39258","Mailcow Dockerized Swagger UI - Cross-Site Scripting","2026-08-31T00:00:00Z",{"id":244,"detectable_with":245,"vuln_details":248,"vuln_id":262,"name":263,"published":242,"updated":106},29672,{"tool":246,"engine":247},{"id":112,"name":113},{"id":115,"name":116},{"id":244,"codename":106,"description":106,"severity":121,"risk_description":249,"public_description":250,"public_recommendation":251,"recommendation":106,"references":252,"cvssv3":127,"epss_score":257,"epss_percentile":258,"cve":259,"in_cisa_catalog":9,"date":261,"software_type":106,"vendor":106,"product":106,"ptt_exploit_capabilities":106},"The risk exists that a remote unauthenticated attacker could exploit this vulnerability to read sensitive information from arbitrary files located on the file system of the server.","DB-GPT through 0.8.1 allows unauthenticated arbitrary file writes via a path traversal in the user_id HTTP header of the POST \u002Fapi\u002Fv1\u002Fpython\u002Ffile\u002Fupload endpoint, letting attackers escape the intended upload directory and write files anywhere, as confirmed by the reflected upload path in the JSON response.","Upgrade DB-GPT to a version that validates the user_id header and confines the resolved upload path to the python_uploads directory.",[253,254,255,256],"https:\u002F\u002Fwww.vulncheck.com\u002Fadvisories\u002Fdb-gpt-path-traversal-arbitrary-file-write-via-user-id-header","https:\u002F\u002Fgithub.com\u002Feosphoros-ai\u002FDB-GPT\u002Fissues\u002F3104","https:\u002F\u002Fgithub.com\u002Feosphoros-ai\u002FDB-GPT\u002Fcommit\u002Fe0c741bd2b5e521b128cffb3f68982dde3f7b359","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-73034",0.05122,0.91814,[260],"CVE-2026-73034","2026-08-11T00:00:00Z","NETSCAN-NUCLEI-CVE-CVE-2026-73034","DB-GPT \u003C= 0.8.1 - Arbitrary File Write",{"id":265,"detectable_with":266,"vuln_details":269,"vuln_id":281,"name":282,"published":242,"updated":106},29673,{"tool":267,"engine":268},{"id":112,"name":113},{"id":115,"name":116},{"id":265,"codename":106,"description":106,"severity":121,"risk_description":270,"public_description":271,"public_recommendation":272,"recommendation":106,"references":273,"cvssv3":127,"epss_score":276,"epss_percentile":277,"cve":278,"in_cisa_catalog":9,"date":280,"software_type":106,"vendor":106,"product":106,"ptt_exploit_capabilities":106},"Successful exploitation can disclose camera authentication credentials to an unauthenticated remote attacker, potentially allowing unauthorized access to the affected device.","GoAhead camera credential disclosure vulnerability in system.ini. The vulnerability affects certain Wireless IP Camera (P2P) WIFICAM devices and allows unauthenticated remote attackers to access the system.ini configuration file through a crafted HTTP request. The exposed configuration may contain sensitive authentication credentials, including usernames and passwords.","Update affected camera firmware to the latest available version. Where firmware updates are unavailable, restrict access to the camera's HTTP interface and avoid exposing the device directly to untrusted networks.",[274,275],"https:\u002F\u002Fgithub.com\u002FK3ysTr0K3R\u002FCVE-2017-8225-EXPLOIT","https:\u002F\u002Fcve.mitre.org\u002Fcgi-bin\u002Fcvename.cgi?name=CVE-2017-8225",0.35359,0.98337,[279],"CVE-2017-8225","2017-04-25T00:00:00Z","NETSCAN-NUCLEI-CVE-CVE-2017-8225","GoAhead Camera - Credential Disclosure",{"id":284,"detectable_with":285,"vuln_details":288,"vuln_id":299,"name":300,"published":242,"updated":106},29674,{"tool":286,"engine":287},{"id":112,"name":113},{"id":115,"name":116},{"id":284,"codename":106,"description":106,"severity":121,"risk_description":106,"public_description":289,"public_recommendation":290,"recommendation":106,"references":291,"cvssv3":127,"epss_score":294,"epss_percentile":295,"cve":296,"in_cisa_catalog":9,"date":298,"software_type":106,"vendor":106,"product":106,"ptt_exploit_capabilities":106},"Gotenberg before 8.31.0 is vulnerable to server-side request forgery (SSRF) due to insufficient validation of URLs in the downloadFrom API. An unauthenticated attacker can exploit the flaw by providing specially crafted IPv4-mapped IPv6 addresses (such as http:\u002F\u002F[::ffff:127.0.0.1]) that bypass the deny-list and allow access to internal resources. Fixed versions properly recognize these addresses and prevent such requests.","We recommend you to upgrade the affected software to the latest version, which mitigates this vulnerability.",[292,293],"https:\u002F\u002Fgithub.com\u002Fgotenberg\u002Fgotenberg\u002Fsecurity\u002Fadvisories\u002FGHSA-4vmc-gm8v-m35h","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-42596",0.01239,0.67102,[297],"CVE-2026-42596","2026-05-14T00:00:00Z","NETSCAN-NUCLEI-CVE-CVE-2026-42596","Gotenberg \u003C 8.31.0 - Server-Side Request Forgery",{"id":302,"detectable_with":303,"vuln_details":306,"vuln_id":319,"name":320,"published":321,"updated":106},29665,{"tool":304,"engine":305},{"id":112,"name":113},{"id":115,"name":116},{"id":302,"codename":106,"description":106,"severity":172,"risk_description":249,"public_description":307,"public_recommendation":308,"recommendation":106,"references":309,"cvssv3":313,"epss_score":314,"epss_percentile":315,"cve":316,"in_cisa_catalog":9,"date":318,"software_type":106,"vendor":106,"product":106,"ptt_exploit_capabilities":106},"Amazon rabbitmq-aws versions 0.1.0 through 0.2.0 contain active debug code in the ARN resolver. An authenticated RabbitMQ user with management API access can submit an arn:aws-debug:file ARN to the validation endpoint and read arbitrary files accessible to the RabbitMQ process.","Upgrade rabbitmq-aws to version 0.2.1 or later. If upgrading is not immediately possible, disable the aws plugin and rotate secrets stored in files that the RabbitMQ process could read.",[310,311,312],"https:\u002F\u002Fgithub.com\u002Famazon-mq\u002Frabbitmq-aws\u002Fsecurity\u002Fadvisories\u002FGHSA-8554-wg4r-7hxm","https:\u002F\u002Faws.amazon.com\u002Fsecurity\u002Fsecurity-bulletins\u002F2026-034-aws\u002F","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-9133",7.7,0.01039,0.61682,[317],"CVE-2026-9133","2026-05-20T00:00:00Z","NETSCAN-NUCLEI-CVE-CVE-2026-9133","Amazon rabbitmq-aws 0.1.0 through 0.2.0 - Arbitrary File Read","2026-08-30T00:00:00Z",{"id":323,"detectable_with":324,"vuln_details":327,"vuln_id":334,"name":335,"published":321,"updated":106},29668,{"tool":325,"engine":326},{"id":112,"name":113},{"id":115,"name":116},{"id":323,"codename":106,"description":106,"severity":226,"risk_description":328,"public_description":329,"public_recommendation":330,"recommendation":106,"references":331,"cvssv3":106,"epss_score":106,"epss_percentile":106,"cve":106,"in_cisa_catalog":9,"date":106,"software_type":106,"vendor":106,"product":106,"ptt_exploit_capabilities":106},"The risk exists that the data is unknowingly exposed to the internet, making it accessible to remote threat actors that can leverage it to attack the target, or the entire company, depending on the sensitivity of the data.","Grafana Loki API is accessible without authentication, allowing unauthorized access to log streams.","We suggest restricting access to the exposed resource.",[332,333],"https:\u002F\u002Fgrafana.com\u002Fdocs\u002Floki\u002Flatest\u002Foperations\u002Fauthentication\u002F","https:\u002F\u002Fgrafana.com\u002Fdocs\u002Floki\u002Flatest\u002Freference\u002Floki-http-api\u002F","NETSCAN-NUCLEI-EXPOSURES-GRAFANA-LOKI-API-EXPOSURE","Grafana Loki - Unauthenticated API Access",{"id":337,"detectable_with":338,"vuln_details":341,"vuln_id":346,"name":347,"published":321,"updated":106},29670,{"tool":339,"engine":340},{"id":112,"name":113},{"id":115,"name":116},{"id":337,"codename":106,"description":106,"severity":342,"risk_description":328,"public_description":343,"public_recommendation":330,"recommendation":106,"references":344,"cvssv3":106,"epss_score":106,"epss_percentile":106,"cve":106,"in_cisa_catalog":9,"date":106,"software_type":106,"vendor":106,"product":106,"ptt_exploit_capabilities":106},"low","VictoriaMetrics vmagent targets endpoint is exposed without authentication, leaking internal service inventory and scrape configuration.",[345],"https:\u002F\u002Fdocs.victoriametrics.com\u002Fvictoriametrics\u002Fvmagent\u002F","NETSCAN-NUCLEI-EXPOSURES-VICTORIAMETRICS-VMAGENT-API-EXPOSURE","VictoriaMetrics vmagent - Unauthenticated Targets Exposure",{"id":349,"detectable_with":350,"vuln_details":353,"vuln_id":368,"name":369,"published":321,"updated":106},29667,{"tool":351,"engine":352},{"id":112,"name":113},{"id":115,"name":116},{"id":349,"codename":106,"description":106,"severity":226,"risk_description":354,"public_description":355,"public_recommendation":356,"recommendation":106,"references":357,"cvssv3":362,"epss_score":363,"epss_percentile":364,"cve":365,"in_cisa_catalog":9,"date":367,"software_type":106,"vendor":106,"product":106,"ptt_exploit_capabilities":106},"Authenticated attackers with administrator-level access can inject scripts that execute in other users' browsers.","The WP Content Permission plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'ohmem-message' parameter in all versions up to, and including, 1.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Administrator-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.","Update WP Content Permission to a version newer than 1.2.",[358,359,360,361],"https:\u002F\u002Fwww.wordfence.com\u002Fthreat-intel\u002Fvulnerabilities\u002Fid\u002Fe44403cd-1cee-43c4-aabc-3eaad433c020?source=cve","https:\u002F\u002Fplugins.trac.wordpress.org\u002Fbrowser\u002Fwp-content-permission\u002Ftags\u002F1.2\u002Fadmin\u002Fviews\u002Fadmin.php#L74","https:\u002F\u002Fplugins.trac.wordpress.org\u002Fbrowser\u002Fwp-content-permission\u002Ftrunk\u002Fadmin\u002Fviews\u002Fadmin.php#L74","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-0743",4.4,0.00576,0.45288,[366],"CVE-2026-0743","2026-02-04T00:00:00Z","NETSCAN-NUCLEI-CVE-CVE-2026-0743","WP Content Permission \u003C= 1.2 - Cross-Site Scripting",{"id":371,"detectable_with":372,"vuln_details":375,"vuln_id":388,"name":389,"published":321,"updated":106},29666,{"tool":373,"engine":374},{"id":112,"name":113},{"id":115,"name":116},{"id":371,"codename":106,"description":106,"severity":172,"risk_description":249,"public_description":376,"public_recommendation":377,"recommendation":106,"references":378,"cvssv3":382,"epss_score":383,"epss_percentile":384,"cve":385,"in_cisa_catalog":9,"date":387,"software_type":106,"vendor":106,"product":106,"ptt_exploit_capabilities":106},"Kirby CMS versions 5.3.0 through 5.4.0 are vulnerable to a path traversal vulnerability via the \u002Fapi\u002Fauth\u002Flogin endpoint. An unauthenticated attacker may supply a specially crafted email value in the request body containing traversal sequences (such as \"..\u002F..\"), which the application concatenates directly into a filesystem path when hydrating user objects. This can result in the resolution of paths outside the intended accounts directory and may lead to the inclusion of unintended files such as index.php, causing a denial of service by exhausting memory limits. The issue is addressed in version 5.4.1 by properly validating and sanitizing the user-supplied input to prevent directory traversal.","Update to version 5.4.1 or later.",[379,380,381],"https:\u002F\u002Fgithub.com\u002Fgetkirby\u002Fkirby\u002Fsecurity\u002Fadvisories\u002FGHSA-9hx7-c53c-v6x8","https:\u002F\u002Fgithub.com\u002Fgetkirby\u002Fkirby\u002Freleases\u002Ftag\u002F5.4.1","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-44177",8.8,0.0177,0.7663,[386],"CVE-2026-44177","2026-07-16T00:00:00Z","NETSCAN-NUCLEI-CVE-CVE-2026-44177","Kirby CMS 5.3.0-5.4.0 - Path Traversal",{"id":391,"detectable_with":392,"vuln_details":395,"vuln_id":408,"name":409,"published":321,"updated":106},29669,{"tool":393,"engine":394},{"id":112,"name":113},{"id":115,"name":116},{"id":391,"codename":106,"description":106,"severity":172,"risk_description":249,"public_description":396,"public_recommendation":397,"recommendation":106,"references":398,"cvssv3":402,"epss_score":403,"epss_percentile":404,"cve":405,"in_cisa_catalog":9,"date":407,"software_type":106,"vendor":106,"product":106,"ptt_exploit_capabilities":106},"Gotenberg before 8.34.0 allows SSRF and limited local file disclosure via its \u002Fforms\u002Flibreoffice\u002Fconvert endpoint. When LibreOffice is used to convert user-uploaded DOCX files, external relationships within the document (such as a:blip r:link TargetMode=\"External\") can instruct LibreOffice to fetch local resources (file:\u002F\u002F) or remote resources (http\u002Fhttps), which are then included as images in the generated PDF. This can disclose the contents of local files LibreOffice can open as images, or allow outbound requests to attacker-controlled endpoints. Version 8.34.0 disables resolution of external resources during document conversion to mitigate the vulnerability.","Update to version 8.34.0 or later.",[399,400,401],"https:\u002F\u002Fgithub.com\u002Fgotenberg\u002Fgotenberg\u002Fsecurity\u002Fadvisories\u002FGHSA-2mrg-35hw-x3x9","https:\u002F\u002Fgithub.com\u002Fgotenberg\u002Fgotenberg\u002Freleases\u002Ftag\u002Fv8.34.0","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-55229",7.5,0.01514,0.7278,[406],"CVE-2026-55229","2026-07-10T00:00:00Z","NETSCAN-NUCLEI-CVE-CVE-2026-55229","Gotenberg \u003C 8.34.0 - Local File Disclosure",{"id":411,"detectable_with":412,"vuln_details":415,"vuln_id":420,"name":421,"published":198,"updated":106},29663,{"tool":413,"engine":414},{"id":112,"name":113},{"id":115,"name":116},{"id":411,"codename":106,"description":106,"severity":172,"risk_description":328,"public_description":416,"public_recommendation":330,"recommendation":106,"references":417,"cvssv3":106,"epss_score":106,"epss_percentile":106,"cve":106,"in_cisa_catalog":9,"date":106,"software_type":106,"vendor":106,"product":106,"ptt_exploit_capabilities":106},"Detected An Apache Maven settings.xml file is exposed. The server section of this file stores the credentials Maven uses to authenticate to remote repositories and distribution servers, so a public copy can leak repository usernames and passwords.",[418,419],"https:\u002F\u002Fmaven.apache.org\u002Fsettings.html","https:\u002F\u002Fmaven.apache.org\u002Fguides\u002Fmini\u002Fguide-encryption.html","NETSCAN-NUCLEI-EXPOSURES-MAVEN-SETTINGS-XML-EXPOSURE","Apache Maven settings.xml Credentials - Exposure",{"id":423,"detectable_with":424,"vuln_details":427,"vuln_id":432,"name":433,"published":198,"updated":106},29664,{"tool":425,"engine":426},{"id":112,"name":113},{"id":115,"name":116},{"id":423,"codename":106,"description":106,"severity":172,"risk_description":328,"public_description":428,"public_recommendation":330,"recommendation":106,"references":429,"cvssv3":106,"epss_score":106,"epss_percentile":106,"cve":106,"in_cisa_catalog":9,"date":106,"software_type":106,"vendor":106,"product":106,"ptt_exploit_capabilities":106},"Detected A NuGet.config file with a packageSourceCredentials section is exposed. NuGet stores per-feed authentication in this section and often keeps it as a ClearTextPassword, so a public copy leaks the username and password used to reach private package feeds.",[430,431],"https:\u002F\u002Flearn.microsoft.com\u002Fen-us\u002Fnuget\u002Freference\u002Fnuget-config-file","https:\u002F\u002Flearn.microsoft.com\u002Fen-us\u002Fnuget\u002Fconsume-packages\u002Fconsuming-packages-authenticated-feeds","NETSCAN-NUCLEI-EXPOSURES-NUGET-CONFIG-EXPOSURE","NuGet.config Package Source Credentials - Exposure",{"id":435,"detectable_with":436,"vuln_details":439,"vuln_id":453,"name":454,"published":198,"updated":106},29660,{"tool":437,"engine":438},{"id":112,"name":113},{"id":115,"name":116},{"id":435,"codename":106,"description":106,"severity":121,"risk_description":122,"public_description":440,"public_recommendation":441,"recommendation":106,"references":442,"cvssv3":447,"epss_score":448,"epss_percentile":449,"cve":450,"in_cisa_catalog":9,"date":452,"software_type":106,"vendor":106,"product":106,"ptt_exploit_capabilities":106},"Elementor Pro plugin for WordPress in versions \u003C=4.2.1 is vulnerable to unauthenticated arbitrary file upload in the Forms module File Upload field. The validation() and process_field() methods iterate over submitted file entries with different early-exit logic for UPLOAD_ERR_NO_FILE entries. When an attacker submits two file parts for the same upload field — an empty first entry (blank filename triggering UPLOAD_ERR_NO_FILE) followed by a payload — validation() returns early after the empty entry without ever type-checking the payload, while process_field() only skips (continue) the empty entry and moves the payload to wp-content\u002Fuploads\u002Felementor\u002Fforms\u002F. The AJAX action elementor_pro_forms_send_form requires no authentication or nonce.","Update Elementor Pro to version 4.2.2 or later. The fix aligns the validation() and process_field() loops to consistently handle empty file entries.",[443,444,445,446],"https:\u002F\u002Fpatchstack.com\u002Farticles\u002Fcritical-unauthenticated-file-upload-to-rce-in-elementor-pro-plugin\u002F","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-32475","https:\u002F\u002Fgithub.com\u002Fabsholi7ly\u002FElementor-Pro-Unauthenticated-Arbitrary-File-Upload-to-RCE","https:\u002F\u002Fwww.bleepingcomputer.com\u002Fnews\u002Fsecurity\u002Fcritical-elementor-pro-bug-exposes-wordpress-sites-to-rce-attacks\u002F",9,0.02374,0.82725,[451],"CVE-2026-32475","2026-08-19T00:00:00Z","NETSCAN-NUCLEI-CVE-CVE-2026-32475","Elementor Pro \u003C=4.2.1 - Unauthenticated Arbitrary File Upload via Form Handler",{"id":456,"detectable_with":457,"vuln_details":460,"vuln_id":466,"name":467,"published":198,"updated":106},29661,{"tool":458,"engine":459},{"id":112,"name":113},{"id":115,"name":116},{"id":456,"codename":106,"description":106,"severity":172,"risk_description":461,"public_description":462,"public_recommendation":463,"recommendation":106,"references":464,"cvssv3":106,"epss_score":106,"epss_percentile":106,"cve":106,"in_cisa_catalog":9,"date":106,"software_type":106,"vendor":106,"product":106,"ptt_exploit_capabilities":106},"The risk exist that a remote attacker could take advantage of the default credentials for taking over the default account. If an authenticated vulnerability is present on the machine, it could also be leveraged to exploit the target, compromising the underlying system.","Detected Johnson Controls Frick Quantum HD Compressor control panels are accessible with default PIN credentials. These are industrial refrigeration controllers used in cold storage and food processing facilities. Default PINs allow full control of the compressor system.","Change the default login credentials. Use a strong password, at least 10 characters long, preferably randomly generated. Unless the login panel is intended to be exposed to the internet, we strongly recommend placing it behind a firewall.",[465],"https:\u002F\u002Fwww.johnsoncontrols.com\u002Findustrial-refrigeration\u002Ffrick-control-panels-and-control-systems\u002Fquantum-hd-industrial-refrigeration-control-panel","NETSCAN-NUCLEI-DEFAULT-LOGINS-JOHNSON-CONTROLS-DEFAULT-LOGIN","Johnson Controls Frick Quantum HD Compressors - Default Login",{"id":469,"detectable_with":470,"vuln_details":473,"vuln_id":486,"name":487,"published":198,"updated":106},29659,{"tool":471,"engine":472},{"id":112,"name":113},{"id":115,"name":116},{"id":469,"codename":106,"description":106,"severity":121,"risk_description":474,"public_description":475,"public_recommendation":476,"recommendation":106,"references":477,"cvssv3":127,"epss_score":481,"epss_percentile":482,"cve":483,"in_cisa_catalog":9,"date":485,"software_type":106,"vendor":106,"product":106,"ptt_exploit_capabilities":106},"Unauthenticated attackers can read the entire database, exposing sensitive data including credentials and session information.","Joomla Easy Store extension 1.0.0-2.0.1 contains an unauthenticated SQL injection caused by improper validation of order parameters, letting unauthenticated attackers read the full database including credentials and sessions.","Update to the latest version of Easy Store extension.",[478,479,480],"https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-65761","https:\u002F\u002Fmysites.guru\u002Fblog\u002Feasystore-security-disclosure\u002F","https:\u002F\u002Fwww.joomshaper.com\u002Feasystore",0.00928,0.58165,[484],"CVE-2026-65761","2026-07-23T00:00:00Z","NETSCAN-NUCLEI-CVE-CVE-2026-65761","Joomla Easy Store - SQL Injection",{"id":489,"detectable_with":490,"vuln_details":493,"vuln_id":498,"name":499,"published":198,"updated":106},29662,{"tool":491,"engine":492},{"id":112,"name":113},{"id":115,"name":116},{"id":489,"codename":106,"description":106,"severity":172,"risk_description":328,"public_description":494,"public_recommendation":330,"recommendation":106,"references":495,"cvssv3":106,"epss_score":106,"epss_percentile":106,"cve":106,"in_cisa_catalog":9,"date":106,"software_type":106,"vendor":106,"product":106,"ptt_exploit_capabilities":106},"Detected A Python .pypirc configuration file is exposed. This file stores the credentials used by tools like twine and setuptools to upload packages to PyPI or a private package index, and it commonly holds a plaintext password or an upload API token.",[496,497],"https:\u002F\u002Fpackaging.python.org\u002Fen\u002Flatest\u002Fspecifications\u002Fpypirc\u002F","https:\u002F\u002Ftwine.readthedocs.io\u002Fen\u002Fstable\u002F","NETSCAN-NUCLEI-EXPOSURES-PYPIRC-CREDENTIALS-EXPOSURE","Python .pypirc Credentials - Exposure",{"id":501,"detectable_with":502,"vuln_details":505,"vuln_id":522,"name":523,"published":524,"updated":106},29657,{"tool":503,"engine":504},{"id":112,"name":113},{"id":115,"name":116},{"id":501,"codename":106,"description":106,"severity":172,"risk_description":506,"public_description":507,"public_recommendation":508,"recommendation":106,"references":509,"cvssv3":516,"epss_score":517,"epss_percentile":518,"cve":519,"in_cisa_catalog":71,"date":521,"software_type":106,"vendor":106,"product":106,"ptt_exploit_capabilities":106},"Unauthenticated attackers gain administrative access to the RMM console and can reach every managed endpoint through Take Control. Exploited in the wild and added to the CISA Known","N-able N-central versions through 2026.3.1 contain an authentication bypass that lets a remote unauthenticated attacker take over an administrator account and gain full control of the N-central server. CVE-2026-18577 is a bypass of the incomplete fix for CVE-2026-18556, so the 2026.3.1 Hotfix 1 build (2026.3.1.7) does not fully remediate it. Hotfix 2 (2026.3.1.10) supersedes Hotfix 1 and is the first fully fixed 2026.3 build.","Upgrade on-premises N-central to 2026.3.1.10 (2026.3 Hotfix 2) or to a later release line (2026.4 or newer). Applying Hotfix 1 (2026.3.1.7) alone is not sufficient. N-able hosted environments were mitigated by the vendor and need no customer action.",[510,511,512,513,514,515],"https:\u002F\u002Fwww.n-able.com\u002Fblog\u002Fn-central-security-update-august-6-2026","https:\u002F\u002Fstatus.n-able.com\u002F2026\u002F08\u002F06\u002Fn-central-2026-3-hotfix-2-additional-mitigation-for-cve-2026-18577\u002F","https:\u002F\u002Fwww.rapid7.com\u002Fblog\u002Fpost\u002Fetr-cve-2026-18577-n-able-n-central-authentication-bypass-exploited-in-the-wild\u002F","https:\u002F\u002Fwww.huntress.com\u002Fblog\u002Fn-able-vulnerability-exploitation","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-18577","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-18556",8.1,0.54068,0.98931,[520],"CVE-2026-18577","2026-08-02T00:00:00Z","NETSCAN-NUCLEI-CVE-CVE-2026-18577","N-able N-central \u003C 2026.3.1.10 - Authentication Bypass","2026-08-26T00:00:00Z",{"id":526,"detectable_with":527,"vuln_details":530,"vuln_id":546,"name":547,"published":524,"updated":106},29655,{"tool":528,"engine":529},{"id":112,"name":113},{"id":115,"name":116},{"id":526,"codename":106,"description":106,"severity":121,"risk_description":531,"public_description":532,"public_recommendation":533,"recommendation":106,"references":534,"cvssv3":540,"epss_score":541,"epss_percentile":542,"cve":543,"in_cisa_catalog":71,"date":545,"software_type":106,"vendor":106,"product":106,"ptt_exploit_capabilities":106},"Unauthorized attackers can bypass authentication, gaining unauthorized access to protected resources.","Microsoft SharePoint Server is vulnerable to an authentication bypass (CVE-2026-55040) in its JWT token validation pipeline (SPJsonWebSecurityTokenHandlerV2). The chain disables signature requirements (RequireSignedTokens=false, accepting alg:none tokens), resolves the actor token x5t thumbprint against the server's own STS signing certificate (freely retrievable from \u002F_layouts\u002F15\u002Fmetadata\u002Fjson\u002F1) without verifying the signature, accepts unregistered certificate issuers, and only checks the actor token signature is non-empty. An unauthenticated remote attacker can forge a JWT and authenticate as any SharePoint user, including a site administrator. This template forges such a token and confirms the bypass by obtaining a SharePoint form digest.","Update to the latest version of Microsoft Office SharePoint.",[535,536,537,538,539],"https:\u002F\u002Fgithub.com\u002Fsfewer-r7\u002FCVE-2026-55040","https:\u002F\u002Fwww.rapid7.com\u002Fblog\u002Fpost\u002Fra-microsoft-sharepoint-jwt-token-authentication-bypass-cve-2026-55040\u002F","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-55040","https:\u002F\u002Fmsrc.microsoft.com\u002Fupdate-guide\u002Fvulnerability\u002FCVE-2026-55040","https:\u002F\u002Fwww.cisa.gov\u002Fknown-exploited-vulnerabilities-catalog?field_cve=CVE-2026-55040",9.1,0.39652,0.98518,[544],"CVE-2026-55040","2026-07-14T00:00:00Z","NETSCAN-NUCLEI-CVE-CVE-2026-55040","Microsoft SharePoint Server - JWT Authentication Bypass",{"id":549,"detectable_with":550,"vuln_details":553,"vuln_id":568,"name":569,"published":524,"updated":106},29658,{"tool":551,"engine":552},{"id":112,"name":113},{"id":115,"name":116},{"id":549,"codename":106,"description":106,"severity":226,"risk_description":554,"public_description":555,"public_recommendation":556,"recommendation":106,"references":557,"cvssv3":562,"epss_score":563,"epss_percentile":564,"cve":565,"in_cisa_catalog":9,"date":567,"software_type":106,"vendor":106,"product":106,"ptt_exploit_capabilities":106},"An unauthenticated attacker can read the exact Directus version and use it to look up known vulnerabilities in that release or its bundled dependencies.","Directus versions from 9.0.0 before 11.9.0 expose the exact running version through the OpenAPI specification returned by the unauthenticated \u002Fserver\u002Fspecs\u002Foas endpoint. The version is placed in the OpenAPI info.version field, letting an unauthenticated attacker fingerprint the precise Directus release. The fix replaces the exact version in that field with a hashed value.","Upgrade to Directus 11.9.0 or later, where the OpenAPI info.version field no longer contains the exact version.",[558,559,560,561],"https:\u002F\u002Fgithub.com\u002Fdirectus\u002Fdirectus\u002Fsecurity\u002Fadvisories\u002FGHSA-rmjh-cf9q-pv7q","https:\u002F\u002Fgithub.com\u002Fdirectus\u002Fdirectus\u002Fpull\u002F25353","https:\u002F\u002Fgithub.com\u002Fdirectus\u002Fdirectus\u002Fcommit\u002Fe74f3e4e92edc33b5f83eefb001a3d2a85af17a3","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2025-53887",5.3,0.00884,0.56821,[566],"CVE-2025-53887","2025-07-15T00:00:00Z","NETSCAN-NUCLEI-CVE-CVE-2025-53887","Directus \u003C 11.9.0 - Version Disclosure",{"id":571,"detectable_with":572,"vuln_details":575,"vuln_id":587,"name":588,"published":524,"updated":106},29654,{"tool":573,"engine":574},{"id":112,"name":113},{"id":115,"name":116},{"id":571,"codename":106,"description":106,"severity":172,"risk_description":576,"public_description":577,"public_recommendation":578,"recommendation":106,"references":579,"cvssv3":382,"epss_score":583,"epss_percentile":584,"cve":585,"in_cisa_catalog":9,"date":318,"software_type":106,"vendor":106,"product":106,"ptt_exploit_capabilities":106},"Authenticated attackers can insert arbitrary rows into any WordPress database table, allowing creation of a new administrator account and full takeover of the site.","The Read More & Accordion (expand-maker) plugin for WordPress through 3.5.7 allows privilege escalation due to improper validation in the importData AJAX handler (yrm_import_data action). An authenticated user with plugin access can upload a crafted JSON attachment to insert arbitrary rows into WordPress database tables, including those that control user roles and capabilities, potentially leading to site takeover.","Update to the latest version of the Read More & Accordion (expand-maker) plugin.",[580,581,582],"https:\u002F\u002Fwww.wordfence.com\u002Fthreat-intel\u002Fvulnerabilities\u002Fid\u002Fadf51c03-b0bb-4864-b64d-6b0cba4b0130","https:\u002F\u002Fwordpress.org\u002Fplugins\u002Fexpand-maker\u002F","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-7467",0.01242,0.67192,[586],"CVE-2026-7467","NETSCAN-NUCLEI-CVE-CVE-2026-7467","Read More & Accordion \u003C= 3.5.7 - Authenticated Privilege Escalation"]