[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"all-banners":3,"SkipToContent_34xgpJIRRkpiT6ls6jE4NHf7VpvQCQBEwi69exi4oT0":54,"FormattedDate_YGZoki4KbemRpkMkk2LxWIughCHzKqWyXU32hDxuo":61,"FooterNav_JsYsxvLufb1W12aeknKZ89on0MD0bNDTiB5EYxyxmU":68,"FooterSocial_u16tCafBUeGMoDrdLfTINytP2JB5msc6iB3VDUutAoU":74,"$f2r4b9phgo6bha":81,"$f17q7jdn7tll3p":83,"finding-templates-{\"q\":\"\",\"page\":1}":116},[4,15,21,27,33,39,44],{"title":5,"slug":6,"text":7,"link":8,"external":9,"targets":10,"cta":12,"variant":13,"campaign_id":14},"Compliance - Page Launch - Network Scanner","compliance-pages-launch-network-scanner","Scheduled scans are the spine of every compliance framework. Are you audit-ready?","https:\u002F\u002Fpentest-tools.com\u002Fusage\u002Fcompliance",false,[11],"\u002Fnetwork-vulnerability-scanning\u002Fnetwork-security-scanner-online","Get compliance evidence","secondary","compliance-pages-launch",{"title":16,"slug":17,"text":18,"link":8,"external":9,"targets":19,"cta":12,"variant":13,"campaign_id":14},"Compliance - Page Launch - Website Scanner","compliance-pages-launch-website-scanner","Authenticated web-app scans show up in SOC 2, NIS2, and CRA Annex I. See why this is crucial for the business.",[20],"\u002Fwebsite-vulnerability-scanning\u002Fwebsite-scanner",{"title":22,"slug":23,"text":24,"link":8,"external":9,"targets":25,"cta":12,"variant":13,"campaign_id":14},"Compliance - Page Launch - Advanced Pentest Reporting","compliance-pages-launch-reporting","Editable DOCX. Immutable PDF. JSON for the GRC tool. See why these formats are on every auditor's checklist.",[26],"\u002Ffeatures\u002Fpentest-reporting",{"title":28,"slug":29,"text":30,"link":8,"external":9,"targets":31,"cta":12,"variant":13,"campaign_id":14},"Compliance - Page Launch - Integrations","compliance-pages-launch-integrations","Vanta, Jira, webhooks - they all route back to DORA, NIS2, SOC 2, ISO 27001, CRA. See why this is crucial for the business.",[32],"\u002Ffeatures\u002Fintegrations",{"title":34,"slug":35,"text":36,"link":8,"external":9,"targets":37,"cta":12,"variant":13,"campaign_id":14},"Compliance - Page Launch - Sniper","compliance-pages-launch-sniper","Five compliance framework pages now reference Sniper as the source of validated exploitability evidence. See them all.",[38],"\u002Fexploit-helpers\u002Fsniper",{"title":40,"slug":14,"text":41,"link":8,"external":9,"targets":42,"cta":12,"variant":13,"campaign_id":14},"Compliance - Page Launch - Homepage","Turn confirmed vulnerabilities into evidence your auditor accepts. Testing requirements for DORA, NIS2, SOC 2, ISO 27001, and CRA.",[43],"\u002F",{"title":45,"slug":46,"text":47,"link":48,"external":49,"targets":50,"cta":53,"variant":13,"campaign_id":46},"Office Hours #11 - Compliance cycle survey","office-hours-11","[Live Office Hours, Wed Sept 16] Continuous compliance evidence: from automated tools or tired humans?","https:\u002F\u002Fzoom.us\u002Fwebinar\u002Fregister\u002F5117815316917\u002FWN_FLMs2-vyQbCTB67guMJH-Q",true,[51,52],"\u002Finsights\u002Fcompliance-cycles-survey","\u002Finsights","Save your spot",["Island",55],{"key":56,"params":57,"result":59},"SkipToContent_34xgpJIRRkpiT6ls6jE4NHf7VpvQCQBEwi69exi4oT0",{"props":58},"{}",{"head":60},{},["Island",62],{"key":63,"params":64,"result":66},"FormattedDate_YGZoki4KbemRpkMkk2LxWIughCHzKqWyXU32hDxuo",{"props":65},"{\"date\":1778569448,\"format\":\"MMMM dd, yyyy\"}",{"head":67},{},["Island",69],{"key":70,"params":71,"result":72},"FooterNav_JsYsxvLufb1W12aeknKZ89on0MD0bNDTiB5EYxyxmU",{"props":58},{"head":73},{},["Island",75],{"key":76,"params":77,"result":79},"FooterSocial_u16tCafBUeGMoDrdLfTINytP2JB5msc6iB3VDUutAoU",{"props":78},"{\"text-color\":\"gray\"}",{"head":80},{},{"count":82},199,{"count":84,"next":85,"previous":86,"results":87},17411,"https:\u002F\u002Fvulndb.pentest-tools.com\u002Fapi\u002Fvulns\u002F?page=2&page_size=1",null,[88],{"id":89,"detectable_with":90,"vuln_details":97,"vuln_id":113,"name":114,"published":115,"updated":86},29731,{"tool":91,"engine":94},{"id":92,"name":93},1,"Network Scanner",{"id":95,"name":96},2,"Nuclei",{"id":89,"epss_score":98,"epss_percentile":99,"in_cisa_catalog":9,"codename":86,"public_description":100,"description":86,"severity":101,"risk_description":102,"public_recommendation":103,"recommendation":86,"references":104,"cvssv3":108,"cve":109,"date":111,"software_type":86,"vendor":112,"product":112,"ptt_exploit_capabilities":86,"category":86},0.00461,0.3873,"Discourse versions before 2026.1.2, 2026.2.1, and 2026.3.0-latest.1 contain an authorization bypass in PostsController#display_post. The controller calls post.revert_to(params[:version]) directly whenever a version query parameter is present, without checking whether the corresponding PostRevision is hidden or whether the caller has permission to view edit history. By requesting a post at its publicly known version number via GET \u002Fposts\u002F:id.json?version=\u003Cpublic_version>, the next PostRevision's stored modifications are applied unconditionally. If staff have hidden that revision, its pre-edit content is returned to an unauthenticated caller. On patched installs the same request is rejected with 403 because guardian.ensure_can_see!(post_revision) is evaluated first.","medium","An unauthenticated visitor can retrieve the contents of a hidden post revision that moderators intended to conceal from public viewers.","Upgrade Discourse to 2026.1.2, 2026.2.1, 2026.3.0-latest.1, or later.",[105,106,107],"https:\u002F\u002Fgithub.com\u002Fdiscourse\u002Fdiscourse\u002Fsecurity\u002Fadvisories\u002FGHSA-fq69-f929-wp96","https:\u002F\u002Fgithub.com\u002Fdiscourse\u002Fdiscourse\u002Fcommit\u002F8510fde30eb0d7f2dee822a95f6cf43b9ac943d0","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-27454",5.3,[110],"CVE-2026-27454","2026-03-19T00:00:00Z","discourse","NETSCAN-NUCLEI-CVE-CVE-2026-27454","Discourse \u003C=2026.2.0 - Hidden Post Revision Disclosure via revert_to Authorization Bypass (CVE-2026-27454)","2026-09-15T00:00:00Z",{"count":84,"next":117,"previous":86,"results":118},"https:\u002F\u002Fvulndb.pentest-tools.com\u002Fapi\u002Fvulns\u002F?limit=25&page=2&search=",[119,141,173,193,221,244,266,289,308,328,351,372,380,402,423,443,468,490,512,534,556,577,599,620,643],{"id":120,"detectable_with":121,"vuln_details":124,"vuln_id":139,"name":140,"published":115,"updated":86},29726,{"tool":122,"engine":123},{"id":92,"name":93},{"id":95,"name":96},{"id":120,"codename":86,"description":86,"severity":125,"risk_description":126,"public_description":127,"public_recommendation":128,"recommendation":86,"references":129,"cvssv3":134,"epss_score":86,"epss_percentile":86,"cve":135,"in_cisa_catalog":9,"date":86,"software_type":86,"vendor":137,"product":138,"ptt_exploit_capabilities":86},"high","An unauthenticated network client may access the Device Builder dashboard and its authenticated capabilities, which can lead to unauthorized access to ESPHome projects and device-management operations.","ESPHome Device Builder versions before 1.0.10 bind the trusted Home Assistant ingress site to all interfaces. A client that can reach the ingress port can therefore access the dashboard without the Supervisor's authentication proxy.","Upgrade the ESPHome add-on to a release bundling Device Builder 1.0.10 or later.",[130,131,132,133],"https:\u002F\u002Fgithub.com\u002Fesphome\u002Fdevice-builder\u002Fsecurity\u002Fadvisories\u002FGHSA-vv4j-m4vr-f3g6","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-59177","https:\u002F\u002Fgithub.com\u002Fesphome\u002Fdevice-builder\u002Fpull\u002F1565","https:\u002F\u002Fgithub.com\u002Fesphome\u002Fdevice-builder\u002Fcommit\u002Fb6387db3f8bf1d3df5771f40e9856b959ae4f6a1",8.8,[136],"CVE-2026-59177","esphome","device-builder","NETSCAN-NUCLEI-CVE-CVE-2026-59177","ESPHome Device Builder \u003C1.0.10 - Unauthenticated Dashboard Access",{"id":142,"detectable_with":143,"vuln_details":147,"vuln_id":171,"name":172,"published":115,"updated":115},29733,{"tool":144,"engine":145},{"id":92,"name":93},{"id":92,"name":146},"Sniper",{"id":142,"codename":148,"description":149,"severity":150,"risk_description":151,"public_description":152,"public_recommendation":153,"recommendation":154,"references":155,"cvssv3":160,"epss_score":161,"epss_percentile":162,"cve":163,"in_cisa_catalog":9,"date":165,"software_type":166,"vendor":167,"product":168,"ptt_exploit_capabilities":169},"KindaRails2Shell","We found that the target Ruby on Rails server is vulnerable to CVE-2026-66066 (GHSA-xr9x-r78c-5hrm, nicknamed \"KindaRails2Shell\"), a type confusion vulnerability (CWE-1188) in Active Storage's libvips-based variant processing. By default, Active Storage lets libvips process untrusted, unfuzzed file formats; an attacker can upload a crafted MATLAB 5.0 \u002F HDF5 polyglot blob whose external-link dataset causes libvips to leak an arbitrary server-side file (e.g. \u002Fproc\u002Fself\u002Fenviron) back through the rendered image's pixel data. By leaking SECRET_KEY_BASE this way, an unauthenticated attacker can forge a signed Active Storage variation token carrying an instance_eval payload that Rails evaluates on deserialization, resulting in unauthenticated remote code execution in the context of the Rails process. Exploitation does not require user interaction.\nWe have detected this by uploading a crafted polyglot blob to leak SECRET_KEY_BASE from the target, then forging a variation token to execute the id command and retrieving its output back through the same file-read primitive.","critical","The risk exists that a remote unauthenticated attacker can fully compromise the server to steal confidential information, install ransomware, or pivot to the internal network.","Ruby on Rails Active Storage, when using the default libvips image variant processor, is vulnerable to CVE-2026-66066 (\"KindaRails2Shell\"), a type confusion vulnerability that lets an unauthenticated attacker read arbitrary files from the server and, by leaking the application's SECRET_KEY_BASE, forge a signed request that leads to remote code execution.","Update Ruby on Rails Active Storage to version 7.2.3.2, 8.0.5.1, 8.1.3.1 or later, and rotate SECRET_KEY_BASE and other application credentials.","We recommend updating the activestorage gem to version 7.2.3.2, 8.0.5.1, 8.1.3.1 or later, ensuring libvips is upgraded to version 8.13 or later, and rotating SECRET_KEY_BASE, the Rails master key, and any other credentials the application process could read, since they may already have been exposed.",[156,157,158,159],"https:\u002F\u002Fgithub.com\u002Frails\u002Frails\u002Fsecurity\u002Fadvisories\u002FGHSA-xr9x-r78c-5hrm","https:\u002F\u002Fdiscuss.rubyonrails.org\u002Ft\u002Fcve-2026-66066-possible-arbitrary-file-read-and-remote-code-execution-in-active-storage-variant-processing\u002F91432","https:\u002F\u002Fwww.openwall.com\u002Flists\u002Foss-security\u002F2026\u002F07\u002F29\u002F9","https:\u002F\u002Fadvisories.gitlab.com\u002Fgem\u002Factivestorage\u002FCVE-2026-66066\u002F",10,0.27861,0.97982,[164],"CVE-2026-66066","2026-07-29T00:00:00Z","Shared library","Rails","Active Storage",[170],"RCE","NETSCAN-SNIPER-CVE-2026-66066","Ruby on Rails Active Storage - Remote Code Execution",{"id":174,"detectable_with":175,"vuln_details":178,"vuln_id":191,"name":192,"published":115,"updated":86},29729,{"tool":176,"engine":177},{"id":92,"name":93},{"id":95,"name":96},{"id":174,"codename":86,"description":86,"severity":125,"risk_description":179,"public_description":180,"public_recommendation":181,"recommendation":86,"references":182,"cvssv3":185,"epss_score":186,"epss_percentile":187,"cve":188,"in_cisa_catalog":9,"date":190,"software_type":86,"vendor":112,"product":112,"ptt_exploit_capabilities":86},"Any user, including anonymous, can bulk exfiltrate private user data such as phone numbers and addresses.","Discourse prior to 2025.12.2, 2026.1.1, and 2026.2.0 contains an IDOR vulnerability caused by lack of authorization checks on user_field_ids parameter in DirectoryItemsController#index, letting any user retrieve private user field values, exploit requires no authentication.","Update to versions 2025.12.2, 2026.1.1, or 2026.2.0 or later.",[183,184],"https:\u002F\u002Fgithub.com\u002Fdiscourse\u002Fdiscourse\u002Fsecurity\u002Fadvisories\u002FGHSA-crxf-p6jm-vpgw","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-26265",7.5,0.00266,0.18764,[189],"CVE-2026-26265","2026-02-26T00:00:00Z","NETSCAN-NUCLEI-CVE-CVE-2026-26265","Discourse - Private User Field Disclosure via Directory Items IDOR",{"id":194,"detectable_with":195,"vuln_details":198,"vuln_id":219,"name":220,"published":115,"updated":115},29735,{"tool":196,"engine":197},{"id":92,"name":93},{"id":92,"name":146},{"id":194,"codename":86,"description":199,"severity":150,"risk_description":200,"public_description":201,"public_recommendation":202,"recommendation":203,"references":204,"cvssv3":209,"epss_score":210,"epss_percentile":211,"cve":212,"in_cisa_catalog":49,"date":214,"software_type":215,"vendor":216,"product":217,"ptt_exploit_capabilities":218},"We found that the target server is running JetBrains TeamCity On-Premises in a version older than 2026.1.3 or 2025.11.7, which is vulnerable to unauthenticated remote code execution through the agent polling protocol. The endpoints under \u002Fapp\u002Fagents\u002Fv1\u002F are reachable without authentication and deserialize attacker-supplied XML using XStream. The root cause is that XStreamHolder.setupSecurityIfNeeded() applies its allowlist without first clearing XStream's default type permissions with NoTypePermission.NONE, so the permissive defaults covering the Map and Throwable hierarchies remain in effect and the allowlist is additive rather than exclusive. After registering an agent session on \u002Fapp\u002Fagents\u002Fv1\u002Fregister, an attacker can post a crafted object graph to \u002Fapp\u002Fagents\u002Fv1\u002Fcommands\u002Ferror that chains a TeamCity exception class, a FreeMarker bean wrapper and a TiedMapEntry to reach BasicDataSource.getConnection(). Opening that connection runs attacker-controlled init SQL against an in-memory HSQLDB, whose SCRIPT statement writes a polyglot SQL\u002FJSP file into the TeamCity web root, which the server then compiles and executes on the next request.","The risk exists that a remote unauthenticated attacker can fully compromise the server to steal confidential information, install ransomware, or pivot to the internal network. Because TeamCity is a build server, code execution also exposes stored CI\u002FCD credentials, signing keys and source code, which can be abused to tamper with build artifacts and reach downstream production systems. The vulnerability is rated critical, requires no authentication, has public exploit code available and is confirmed to be exploited in the wild.","JetBrains TeamCity On-Premises versions before 2026.1.3 and 2025.11.7 are vulnerable to unauthenticated remote code execution via the agent polling protocol. The agent endpoints are exposed without authentication and deserialize untrusted XML with XStream using an incorrectly configured allowlist, which leaves the library's permissive default type permissions in place. An attacker who can reach the TeamCity server over the network can register an agent session and submit a crafted object graph that writes an executable file into the server's web root and runs arbitrary code, without any credentials or user interaction. This vulnerability is listed in the CISA Known Exploited Vulnerabilities catalog and has been observed being exploited in the wild.","Update JetBrains TeamCity On-Premises to version 2026.1.3 or 2025.11.7 or later, or apply the vendor-provided security patch plugin.","We recommend upgrading JetBrains TeamCity On-Premises to version 2026.1.3 or 2025.11.7 or later. If an immediate upgrade is not possible, JetBrains provides a security patch plugin for TeamCity 2017.1 and newer that addresses this issue, and access to the server and its agent endpoints should be restricted at the network boundary in the meantime. Because this vulnerability is known to be exploited in the wild, we also recommend reviewing the server for unexpected files in the web root, unknown agent registrations, and rotating any credentials stored in TeamCity.",[205,206,207,208],"https:\u002F\u002Fblog.jetbrains.com\u002Fteamcity\u002F2026\u002F07\u002Fcve-2026-63077\u002F","https:\u002F\u002Fwww.rapid7.com\u002Fblog\u002Fpost\u002Fetr-cve-2026-63077-critical-unauthenticated-remote-code-execution-in-jetbrains-teamcity\u002F","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-63077","https:\u002F\u002Fwww.cisa.gov\u002Fknown-exploited-vulnerabilities-catalog?field_cve=CVE-2026-63077",9.8,0.86518,0.99726,[213],"CVE-2026-63077","2026-07-27T00:00:00Z","Continuous Integration Server","JetBrains","TeamCity",[170],"NETSCAN-SNIPER-CVE-2026-63077","JetBrains TeamCity - Remote Code Execution",{"id":222,"detectable_with":223,"vuln_details":226,"vuln_id":242,"name":243,"published":115,"updated":86},29721,{"tool":224,"engine":225},{"id":92,"name":93},{"id":95,"name":96},{"id":222,"codename":86,"description":86,"severity":150,"risk_description":227,"public_description":228,"public_recommendation":229,"recommendation":86,"references":230,"cvssv3":234,"epss_score":235,"epss_percentile":236,"cve":237,"in_cisa_catalog":9,"date":239,"software_type":86,"vendor":240,"product":241,"ptt_exploit_capabilities":86},"Malicious websites can perform authenticated API requests to exfiltrate or delete data, leading to data loss and information disclosure.","LightRAG \u003C= 1.5.4 contains a broken access control vulnerability caused by default CORS_ORIGINS=* with allow_credentials=True in lightrag_server.py, letting malicious websites perform authenticated API requests, exploit requires authenticated user.","Update to version 1.5.4 or later.",[231,232,233],"https:\u002F\u002Fgithub.com\u002FHKUDS\u002FLightRAG\u002Fsecurity\u002Fadvisories\u002FGHSA-6x6h-qqr7-855w","https:\u002F\u002Fgithub.com\u002FHKUDS\u002FLightRAG\u002Fcommit\u002F09567a4c983f580050db63569dd477122c058c3d","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-61736",9.3,0.00532,0.4335,[238],"CVE-2026-61736","2026-07-15T00:00:00Z","hkuds","lightrag","NETSCAN-NUCLEI-CVE-CVE-2026-61736","LightRAG \u003C= 1.5.3 - Credentialed CORS Wildcard",{"id":245,"detectable_with":246,"vuln_details":249,"vuln_id":264,"name":265,"published":115,"updated":86},29730,{"tool":247,"engine":248},{"id":92,"name":93},{"id":95,"name":96},{"id":245,"codename":86,"description":86,"severity":125,"risk_description":250,"public_description":251,"public_recommendation":252,"recommendation":86,"references":253,"cvssv3":185,"epss_score":257,"epss_percentile":258,"cve":259,"in_cisa_catalog":9,"date":261,"software_type":86,"vendor":262,"product":263,"ptt_exploit_capabilities":86},"The risk exists that a remote unauthenticated attacker could exploit this vulnerability to read sensitive information from arbitrary files located on the file system of the server.","HSC MailInspector 5.3.3-7 contains a path traversal caused by improper validation of user-supplied input in \u002Ftap\u002Fdw.php text parameter, letting remote attackers access arbitrary files, exploit requires crafted request.","Update to the latest version.",[254,255,256],"https:\u002F\u002Fgithub.com\u002Fsql3t0\u002Fcve-disclosures\u002Fblob\u002Fmain\u002F02_-_CVE-2026-29963_LFI%2BPath_Traversal.md","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-29963","https:\u002F\u002Fhsclabs.com\u002Fpt-br\u002Fmailinspector\u002F",0.00595,0.46587,[260],"CVE-2026-29963","2026-05-18T00:00:00Z","hsclabs","mailinspector","NETSCAN-NUCLEI-CVE-CVE-2026-29963","HSC MailInspector - Unauthenticated Arbitrary File Read",{"id":267,"detectable_with":268,"vuln_details":271,"vuln_id":287,"name":288,"published":115,"updated":86},29725,{"tool":269,"engine":270},{"id":92,"name":93},{"id":95,"name":96},{"id":267,"codename":86,"description":86,"severity":125,"risk_description":272,"public_description":273,"public_recommendation":274,"recommendation":86,"references":275,"cvssv3":279,"epss_score":280,"epss_percentile":281,"cve":282,"in_cisa_catalog":9,"date":284,"software_type":86,"vendor":285,"product":286,"ptt_exploit_capabilities":86},"An unauthenticated attacker can execute arbitrary JavaScript in a victim's browser when they open the crafted gallery-tag link, enabling session theft, credential capture, and actions performed as the victim.","NextGEN Gallery through 4.2.3 reflects a URL-decoded `ngg_tag` route value into the generated tag page without the context-specific escaping added in 4.2.4. An unauthenticated attacker can break out of the tag context and inject an auto-executing script. This template injects an `svg onload` payload carrying a random nonce and matches its unencoded reflection; slash and backtick syntax keep the request off common WAF signatures.","Update NextGEN Gallery to version 4.2.4 or later.",[276,277,278],"https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-28141","https:\u002F\u002Fpatchstack.com\u002Fdatabase\u002Fwordpress\u002Fplugin\u002Fnextgen-gallery\u002Fvulnerability\u002Fwordpress-nextgen-gallery-plugin-4-2-3-cross-site-scripting-xss-vulnerability?_s_id=cve","https:\u002F\u002Fwordpress.org\u002Fplugins\u002Fnextgen-gallery\u002F",7.1,0.00175,0.07164,[283],"CVE-2026-28141","2026-08-06T00:00:00Z","imagely","nextgen-gallery","NETSCAN-NUCLEI-CVE-CVE-2026-28141","NextGEN Gallery \u003C= 4.2.3 - Reflected Cross-Site Scripting",{"id":290,"detectable_with":291,"vuln_details":294,"vuln_id":306,"name":307,"published":115,"updated":86},29724,{"tool":292,"engine":293},{"id":92,"name":93},{"id":95,"name":96},{"id":290,"codename":86,"description":86,"severity":125,"risk_description":250,"public_description":295,"public_recommendation":252,"recommendation":86,"references":296,"cvssv3":185,"epss_score":300,"epss_percentile":301,"cve":302,"in_cisa_catalog":9,"date":304,"software_type":86,"vendor":305,"product":305,"ptt_exploit_capabilities":86},"Docmost v0.21.0 contains a path traversal caused by improper handling of avatar attachments, letting unauthenticated attackers disclose local files via a POST request on a public URL.",[297,298,299],"https:\u002F\u002Fwww.artresilia.com\u002Fdocmost-v0-21-0-cve-2025-57231-unauthenticated-file-path-traversal","https:\u002F\u002Fgithub.com\u002Fadvisories\u002FGHSA-59m3-fj8c-996g","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2025-57231",0.00387,0.32253,[303],"CVE-2025-57231","2026-09-10T00:00:00Z","docmost","NETSCAN-NUCLEI-CVE-CVE-2025-57231","Docmost 0.2.1-0.21.0 - Arbitrary File Read",{"id":309,"detectable_with":310,"vuln_details":313,"vuln_id":326,"name":327,"published":115,"updated":86},29718,{"tool":311,"engine":312},{"id":92,"name":93},{"id":95,"name":96},{"id":309,"codename":86,"description":86,"severity":150,"risk_description":151,"public_description":314,"public_recommendation":315,"recommendation":86,"references":316,"cvssv3":209,"epss_score":319,"epss_percentile":320,"cve":321,"in_cisa_catalog":9,"date":323,"software_type":86,"vendor":324,"product":325,"ptt_exploit_capabilities":86},"Langflow \u003C= 1.2.x exposes POST \u002Fapi\u002Fv1\u002Fvalidate\u002Fcode without any authentication. The endpoint calls validate_code() which exec()s user-supplied Python code. Default-argument expressions in Python execute at function-definition time, allowing arbitrary OS command execution without authentication.","Upgrade Langflow to a version that requires authentication on the validate\u002Fcode endpoint.",[317,318],"https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-0768","https:\u002F\u002Fwww.pruva.dev\u002Freproductions\u002FREPRO-2026-00342",0.0231,0.82428,[322],"CVE-2026-0768","2026-01-23T00:00:00Z","langflow-ai","langflow","NETSCAN-NUCLEI-CVE-CVE-2026-0768","Langflow \u003C=1.2.x - Unauthenticated Remote Code Execution via validate_code",{"id":329,"detectable_with":330,"vuln_details":333,"vuln_id":349,"name":350,"published":115,"updated":86},29728,{"tool":331,"engine":332},{"id":92,"name":93},{"id":95,"name":96},{"id":329,"codename":86,"description":86,"severity":101,"risk_description":334,"public_description":335,"public_recommendation":336,"recommendation":86,"references":337,"cvssv3":342,"epss_score":343,"epss_percentile":344,"cve":345,"in_cisa_catalog":9,"date":347,"software_type":86,"vendor":348,"product":348,"ptt_exploit_capabilities":86},"Remote attackers can execute arbitrary JavaScript on the server origin, potentially leading to session hijacking or further attacks.","Appium \u003C= 10.7.0 contains a reflected XSS caused by unescaped reflection of throwError query parameter, comments POST field, and User-Agent header in base-driver routes, letting remote attackers execute arbitrary JavaScript, exploit requires crafted HTTP requests.","Update to version 10.7.0 or later.",[338,339,340,341],"https:\u002F\u002Fgithub.com\u002Fappium\u002Fappium\u002Fsecurity\u002Fadvisories\u002FGHSA-3wgp-x9p5-c7cc","https:\u002F\u002Fgithub.com\u002Fappium\u002Fappium\u002Fcommit\u002Fd94a40af9f8040191ee7888571a1c9d5aec59f89","https:\u002F\u002Fgithub.com\u002Fappium\u002Fappium\u002Freleases\u002Ftag\u002F@appium\u002Fbase-driver@10.7.0","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-58191",6.5,0.00252,0.16693,[346],"CVE-2026-58191","2026-07-08T00:00:00Z","appium","NETSCAN-NUCLEI-CVE-CVE-2026-58191","Appium base-driver \u003C=10.6.0 - Reflected Cross-Site Scripting",{"id":352,"detectable_with":353,"vuln_details":356,"vuln_id":370,"name":371,"published":115,"updated":86},29716,{"tool":354,"engine":355},{"id":92,"name":93},{"id":95,"name":96},{"id":352,"codename":86,"description":86,"severity":150,"risk_description":151,"public_description":357,"public_recommendation":358,"recommendation":86,"references":359,"cvssv3":209,"epss_score":363,"epss_percentile":364,"cve":365,"in_cisa_catalog":9,"date":367,"software_type":86,"vendor":368,"product":369,"ptt_exploit_capabilities":86},"The Divi Form Builder plugin for WordPress versions 5.1.8 and prior contains an unauthenticated arbitrary file upload vulnerability in the do_image_upload() AJAX handler. The user-controlled acceptFileTypes POST parameter is injected unsanitized into a PHP regex for file extension validation. By supplying acceptFileTypes=phtml the constructed regex accepts .phtml files while the plugin's .htaccess only blocks .php, so Apache executes .phtml files as PHP. The required nonce (fb_nonce) is publicly embedded in any page containing a Divi form via the de_fb_obj JavaScript object. Uploaded shells land in \u002Fwp-content\u002Fuploads\u002Fde_fb_uploads\u002F. Fixed in 5.1.9.","Update the Divi Form Builder plugin to version 5.1.9 or later, which validates file extensions without relying on the user-controlled acceptFileTypes parameter.",[360,361,362],"https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-5524","https:\u002F\u002Fgithub.com\u002Fcaterscam\u002FCVE-2026-5524-PoC","https:\u002F\u002Fwpscan.com\u002Fvulnerability\u002FCVE-2026-5524",0.00922,0.58377,[366],"CVE-2026-5524","2026-07-02T00:00:00Z","elegantthemes","divi-form-builder","NETSCAN-NUCLEI-CVE-CVE-2026-5524","Divi Form Builder \u003C=5.1.8 - Unauthenticated Arbitrary File Upload RCE",{"id":89,"detectable_with":373,"vuln_details":376,"vuln_id":113,"name":379,"published":115,"updated":86},{"tool":374,"engine":375},{"id":92,"name":93},{"id":95,"name":96},{"id":89,"codename":86,"description":86,"severity":101,"risk_description":102,"public_description":100,"public_recommendation":103,"recommendation":86,"references":377,"cvssv3":108,"epss_score":98,"epss_percentile":99,"cve":378,"in_cisa_catalog":9,"date":111,"software_type":86,"vendor":112,"product":112,"ptt_exploit_capabilities":86},[105,106,107],[110],"Discourse \u003C=2026.2.0 - Hidden Post Revision Disclosure via revert_to Authorization Bypass",{"id":381,"detectable_with":382,"vuln_details":385,"vuln_id":400,"name":401,"published":115,"updated":86},29720,{"tool":383,"engine":384},{"id":92,"name":93},{"id":95,"name":96},{"id":381,"codename":86,"description":86,"severity":101,"risk_description":386,"public_description":387,"public_recommendation":388,"recommendation":86,"references":389,"cvssv3":392,"epss_score":393,"epss_percentile":394,"cve":395,"in_cisa_catalog":9,"date":397,"software_type":86,"vendor":398,"product":399,"ptt_exploit_capabilities":86},"An unauthenticated attacker who knows a push's secret URL token can permanently delete (expire) any anonymous push, even when the push creator explicitly set deletable_by_viewer to false.","PasswordPusher v1.45.11 through v2.9.5 allows unauthenticated deletion of anonymous pushes due to a nil==nil ownership-check bypass (CWE-863). The deletion guard evaluates (@push.user == current_user) || @push.deletable_by_viewer. For anonymous pushes, @push.user is nil; for unauthenticated requests, current_user is nil. Ruby evaluates nil==nil as true, so the ownership check passes and the deletable_by_viewer=false restriction is completely bypassed. Anyone who knows the secret URL token can permanently expire an anonymous push without any credentials.","Upgrade PasswordPusher to v2.9.6 or later.",[390,391],"https:\u002F\u002Fgithub.com\u002Fpglombardo\u002FPasswordPusher\u002Fsecurity\u002Fadvisories\u002FGHSA-jf2m-hpj9-4qx2","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-62382",6.9,0.00276,0.19973,[396],"CVE-2026-62382","2026-08-22T00:00:00Z","pglombardo","passwordpusher","NETSCAN-NUCLEI-CVE-CVE-2026-62382","PasswordPusher v1.45.11-v2.9.5 - Unauthenticated Anonymous Push Deletion via Ownership Bypass",{"id":403,"detectable_with":404,"vuln_details":407,"vuln_id":421,"name":422,"published":115,"updated":86},29715,{"tool":405,"engine":406},{"id":92,"name":93},{"id":95,"name":96},{"id":403,"codename":86,"description":86,"severity":125,"risk_description":250,"public_description":408,"public_recommendation":409,"recommendation":86,"references":410,"cvssv3":185,"epss_score":414,"epss_percentile":415,"cve":416,"in_cisa_catalog":9,"date":418,"software_type":86,"vendor":419,"product":420,"ptt_exploit_capabilities":86},"GEO my WP WordPress plugin \u003C= 4.5.5.3 contains a local file inclusion caused by improper handling in gmw_posts_locator_ajax_info_window_loader function, letting unauthenticated attackers execute arbitrary PHP code remotely.","Update to the latest version beyond 4.5.5.3.",[411,412,413],"https:\u002F\u002Fwww.wordfence.com\u002Fthreat-intel\u002Fvulnerabilities\u002Fid\u002F562712a8-a42e-4b36-9985-3c71698efdda","https:\u002F\u002Fgithub.com\u002FFitoussi\u002Fgeo-my-wp\u002Fcommit\u002F5a768bf1c6e44ded83a65be8789f3587515665ac","https:\u002F\u002Fplugins.trac.wordpress.org\u002Fbrowser\u002Fgeo-my-wp\u002Ftags\u002F4.5.5.3\u002Fincludes\u002Fgmw-functions.php#L1945",0.00762,0.53349,[417],"CVE-2026-85200","2026-09-12T00:00:00Z","developer.developer","geo-my-wp","NETSCAN-NUCLEI-CVE-CVE-2026-85200","GEO my WP \u003C=4.5.5.3 - Unauthenticated Local File Inclusion",{"id":424,"detectable_with":425,"vuln_details":428,"vuln_id":441,"name":442,"published":115,"updated":86},29719,{"tool":426,"engine":427},{"id":92,"name":93},{"id":95,"name":96},{"id":424,"codename":86,"description":86,"severity":150,"risk_description":151,"public_description":429,"public_recommendation":430,"recommendation":86,"references":431,"cvssv3":435,"epss_score":436,"epss_percentile":437,"cve":438,"in_cisa_catalog":9,"date":304,"software_type":86,"vendor":440,"product":440,"ptt_exploit_capabilities":86},"OmniRoute \u003C= 3.8.49 contains a remote code execution caused by insufficient validation of interpreter arguments in the POST \u002Fapi\u002Facp\u002Fagents endpoint, letting remote attackers execute arbitrary code, exploit requires anonymous access when requireLogin is false or management session\u002FAPI key when true.","Update to the latest version once a fix is available.",[432,433,434],"https:\u002F\u002Fgithub.com\u002Fdiegosouzapw\u002FOmniRoute\u002Fsecurity\u002Fadvisories\u002FGHSA-hf57-cqmx-p4gr","https:\u002F\u002Fgithub.com\u002Fdiegosouzapw\u002FOmniRoute\u002Fpull\u002F11028","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-88062",9.5,0.00403,0.3385,[439],"CVE-2026-88062","omniroute","NETSCAN-NUCLEI-CVE-CVE-2026-88062","OmniRoute \u003C 3.8.49 - Unauthenticated RCE",{"id":444,"detectable_with":445,"vuln_details":448,"vuln_id":466,"name":467,"published":115,"updated":86},29714,{"tool":446,"engine":447},{"id":92,"name":93},{"id":95,"name":96},{"id":444,"codename":86,"description":86,"severity":150,"risk_description":449,"public_description":450,"public_recommendation":451,"recommendation":86,"references":452,"cvssv3":459,"epss_score":460,"epss_percentile":461,"cve":462,"in_cisa_catalog":9,"date":261,"software_type":86,"vendor":464,"product":465,"ptt_exploit_capabilities":86},"Unauthenticated attackers can traverse the Plugin Daemon's internal REST API, leaking system metadata (version hash, platform, pool capacity). Any internal Plugin Daemon endpoint is reachable, meaning any new endpoint becomes instantly exploitable from the public internet without credentials.","Dify version 1.14.1 and prior are affected by an unauthenticated path traversal in the Plugin Daemon icon proxy endpoint. The \u002Fconsole\u002Fapi\u002Fworkspaces\u002Fcurrent\u002Fplugin\u002Ficon endpoint requires no authentication and passes the filename query parameter unsanitized into the internal Plugin Daemon REST API URL. Using ..\u002F dot-sequence traversal an attacker escapes the authorized plugin\u002F{tenant_id}\u002Fasset\u002F namespace and reaches arbitrary internal Plugin Daemon endpoints. The \u002Fhealth\u002Fcheck endpoint is always available and returns Plugin Daemon version, build time and pool status confirming exploitation.","Upgrade to Dify 1.15.0 or later. The fix in api\u002Fcore\u002Fplugin\u002Fimpl\u002Fbase.py (BasePluginClient._prepare_request) URL-decodes the path and raises ValueError on any segment containing .. or %2e%2e, preventing path traversal sequences from being forwarded to the Plugin Daemon.",[453,454,455,456,457,458],"https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-41948","https:\u002F\u002Fwww.zafran.io\u002Fresources\u002Fdifytap-zafran-discovers-how-attackers-can-silently-wiretap-ai-data-across-tenants-on-a-platform-powering-1m-apps","https:\u002F\u002Fhuntr.com\u002Fbounties\u002F35b7ad59-e35d-443f-bf77-387bfb932ec0","https:\u002F\u002Fgithub.com\u002Flanggenius\u002Fdify\u002Fpull\u002F35796","https:\u002F\u002Fosv.dev\u002Fvulnerability\u002FCVE-2026-41948","https:\u002F\u002Fwww.vulncheck.com\u002Fadvisories\u002Fdify-path-traversal-via-plugin-daemon-internal-api-access",9.4,0.0739,0.94074,[463],"CVE-2026-41948","langgenius","dify","NETSCAN-NUCLEI-CVE-CVE-2026-41948","Dify \u003C=1.14.1 - Unauthenticated Plugin Daemon Path Traversal",{"id":469,"detectable_with":470,"vuln_details":473,"vuln_id":488,"name":489,"published":115,"updated":86},29722,{"tool":471,"engine":472},{"id":92,"name":93},{"id":95,"name":96},{"id":469,"codename":86,"description":86,"severity":150,"risk_description":151,"public_description":474,"public_recommendation":475,"recommendation":86,"references":476,"cvssv3":160,"epss_score":481,"epss_percentile":482,"cve":483,"in_cisa_catalog":9,"date":485,"software_type":86,"vendor":486,"product":487,"ptt_exploit_capabilities":86},"CtrlPanel versions \u003C= 1.1.1 are vulnerable to unauthenticated Remote Code Execution (RCE) via the web installer endpoint (public\u002Finstaller\u002Findex.php). The installer loaded and executed form handler files before checking for the install.lock gate, allowing attackers to reach installer forms on fully-deployed instances. User-supplied POST values (url, key, clientkey) from the Pterodactyl configuration form were interpolated directly into shell command strings executed via bash -c without sanitization, enabling command injection. The vulnerability is confirmed actively exploited in the wild.","Update to CtrlPanel v1.2.0 or later. The patch moves the install.lock check to the top of index.php before any form files are loaded, and replaces string-based proc_open() calls with array-style argument lists to prevent shell injection. As an immediate mitigation, deny web server access to the \u002Finstaller\u002F directory.",[477,478,479,480],"https:\u002F\u002Fgithub.com\u002FCtrlpanel-gg\u002Fpanel\u002Fsecurity\u002Fadvisories\u002FGHSA-jmhr-q9q5-fqwh","https:\u002F\u002Fgithub.com\u002Frootdirective-sec\u002FCVE-2026-34234-Lab","https:\u002F\u002Fgithub.com\u002FCtrlpanel-gg\u002Fpanel\u002Freleases\u002Ftag\u002F1.2.0","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-34234",0.00821,0.55259,[484],"CVE-2026-34234","2026-05-19T00:00:00Z","ctrlpanel-gg","ctrlpanel","NETSCAN-NUCLEI-CVE-CVE-2026-34234","CtrlPanel \u003C= 1.1.1 - Remote Code Execution",{"id":491,"detectable_with":492,"vuln_details":495,"vuln_id":510,"name":511,"published":115,"updated":86},29723,{"tool":493,"engine":494},{"id":92,"name":93},{"id":95,"name":96},{"id":491,"codename":86,"description":86,"severity":150,"risk_description":151,"public_description":496,"public_recommendation":497,"recommendation":86,"references":498,"cvssv3":209,"epss_score":503,"epss_percentile":504,"cve":505,"in_cisa_catalog":49,"date":507,"software_type":86,"vendor":508,"product":509,"ptt_exploit_capabilities":86},"Ivanti Endpoint Manager Mobile (EPMM) versions 12.5.0.0 through 12.7.0.0 contain a code injection vulnerability that allows unauthenticated remote attackers to achieve arbitrary code execution on the target system.","Apply the Ivanti security patch for EPMM or upgrade to a version above 12.7.0.0. Restrict network access to the EPMM management interface.",[499,500,501,502],"https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-1281","https:\u002F\u002Fwww.cisa.gov\u002Fknown-exploited-vulnerabilities-catalog","https:\u002F\u002Fwww.helpnetsecurity.com\u002F2026\u002F01\u002F30\u002Fivanti-epmm-cve-2026-1281-cve-2026-1340\u002F","https:\u002F\u002Fwww.cisa.gov\u002Fnews-events\u002Falerts\u002F2026\u002F01\u002F29\u002Fcisa-adds-one-known-exploited-vulnerability-catalog",0.81788,0.99625,[506],"CVE-2026-1281","2026-01-29T00:00:00Z","ivanti","endpoint-manager-mobile","NETSCAN-NUCLEI-CVE-CVE-2026-1281","Ivanti EPMM \u003C=12.7.0.0 - Unauthenticated Code Injection",{"id":513,"detectable_with":514,"vuln_details":517,"vuln_id":532,"name":533,"published":115,"updated":86},29717,{"tool":515,"engine":516},{"id":92,"name":93},{"id":95,"name":96},{"id":513,"codename":86,"description":86,"severity":150,"risk_description":151,"public_description":518,"public_recommendation":519,"recommendation":86,"references":520,"cvssv3":209,"epss_score":525,"epss_percentile":526,"cve":527,"in_cisa_catalog":49,"date":529,"software_type":86,"vendor":530,"product":531,"ptt_exploit_capabilities":86},"PaperCut NG and PaperCut MF versions 24.x through 26.x contain an authentication bypass vulnerability in the Apache Tapestry-based web interface. By crafting a complex-direct service request that specifies the public Home page as the render target while invoking the privileged ConfigEditor page's form listeners, an unauthenticated remote attacker can search and modify server configuration options. PaperCut's access control validates the render page but fails to validate the component page, allowing full configuration access without authentication. When chained with CVE-2026-82078, an attacker reconfigures external user lookup to use a malicious JDBC URL whose initialization SQL evaluates arbitrary Groovy code, achieving unauthenticated remote code execution. This vulnerability is actively exploited in the wild.","Update to PaperCut NG\u002FMF version 26.0.5, 25.0.13, or 24.1.10 or later. As an immediate mitigation, restrict network access to the PaperCut web management interface (default ports 9191 and 9192) to trusted administrative IPs only.",[521,522,523,524],"https:\u002F\u002Fwww.papercut.com\u002Fkb\u002FMain\u002Fsecurity-bulletin-27-aug-2026-urgent-security-advisory\u002F","https:\u002F\u002Fwww.rapid7.com\u002Fblog\u002Fpost\u002Fetr-papercut-ng-mf-critical-zero-day-exploited-in-the-wild\u002F","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-81578","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-82078",0.01617,0.74671,[528],"CVE-2026-81578","2026-08-28T00:00:00Z","papercut","papercut_ng,papercut_mf","NETSCAN-NUCLEI-CVE-CVE-2026-81578","PaperCut NG\u002FMF \u003C=26.0.4 - Unauthenticated ConfigEditor Access via Tapestry Complex-Direct",{"id":535,"detectable_with":536,"vuln_details":539,"vuln_id":554,"name":555,"published":115,"updated":86},29713,{"tool":537,"engine":538},{"id":92,"name":93},{"id":95,"name":96},{"id":535,"codename":86,"description":86,"severity":150,"risk_description":540,"public_description":541,"public_recommendation":542,"recommendation":86,"references":543,"cvssv3":547,"epss_score":548,"epss_percentile":549,"cve":550,"in_cisa_catalog":9,"date":552,"software_type":86,"vendor":553,"product":553,"ptt_exploit_capabilities":86},"An unauthenticated network attacker can read unintended MongoDB data, including administrative usernames and password hashes when local authentication is enabled, by controlling DataTables query parameters.","cve-search versions 4.0 through 6.0.0 expose an unauthenticated DataTables endpoint that accepts attacker-controlled MongoDB collection, projection, filtering, and pagination parameters. This detector uses a harmless invalid projection field against the intended cves collection; version 6.0.1 rejects that field.","Upgrade cve-search to v6.0.1 or later.",[544,545,546],"https:\u002F\u002Fgithub.com\u002Fcve-search\u002Fcve-search\u002Fissues\u002F1217","https:\u002F\u002Fgithub.com\u002Fcve-search\u002Fcve-search\u002Fpull\u002F1218","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-59509",9.2,0.00542,0.43916,[551],"CVE-2026-59509","2026-07-05T00:00:00Z","cve-search","NETSCAN-NUCLEI-CVE-CVE-2026-59509","cve-search 4.0-6.0.0 - Unauthenticated NoSQL Injection",{"id":557,"detectable_with":558,"vuln_details":561,"vuln_id":575,"name":576,"published":115,"updated":86},29727,{"tool":559,"engine":560},{"id":92,"name":93},{"id":95,"name":96},{"id":557,"codename":86,"description":86,"severity":150,"risk_description":151,"public_description":562,"public_recommendation":563,"recommendation":86,"references":564,"cvssv3":209,"epss_score":568,"epss_percentile":569,"cve":570,"in_cisa_catalog":9,"date":572,"software_type":86,"vendor":573,"product":574,"ptt_exploit_capabilities":86},"ruflo MCP bridge (\u003C 3.16.3) in its default docker-compose deployment exposes POST \u002Fmcp with no authentication and binds to all interfaces (0.0.0.0:3001). The executeTool() function has no server-side deny list for dangerous tools, allowing an unauthenticated attacker to invoke tools\u002Fcall with ruflo__terminal_execute, which runs execSync(command) on attacker-supplied input. This yields arbitrary command execution as the node user (uid 1000) inside the bridge container. The blocklist (AUTOPILOT_BLOCKED_PATTERNS + isBlockedTool()) is enforced only in the autopilot SSE handler; POST \u002Fmcp and POST \u002Fmcp\u002F:group bypass it entirely.","Upgrade ruflo to version 3.16.3 or later which adds DANGEROUS_TOOLS gate in executeTool(), bearer auth middleware (MCP_AUTH_TOKEN), loopback bind by default (BIND_HOST=127.0.0.1), and MCP_ENABLE_TERMINAL opt-in. As interim mitigation, firewall port 3001 and set MCP_AUTH_TOKEN in docker-compose.yml.",[565,566,567],"https:\u002F\u002Fgithub.com\u002Fruvnet\u002Fruflo\u002Fsecurity\u002Fadvisories\u002FGHSA-c4hm-4h84-2cf3","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-59726","https:\u002F\u002Fwww.pruva.dev\u002Freproductions\u002FREPRO-2026-00315",0.06883,0.93688,[571],"CVE-2026-59726","2026-07-09T00:00:00Z","ruvnet","ruflo","NETSCAN-NUCLEI-CVE-CVE-2026-59726","ruflo MCP Bridge - Unauthenticated RCE via terminal_execute",{"id":578,"detectable_with":579,"vuln_details":582,"vuln_id":596,"name":597,"published":598,"updated":86},29712,{"tool":580,"engine":581},{"id":92,"name":93},{"id":95,"name":96},{"id":578,"codename":86,"description":86,"severity":150,"risk_description":151,"public_description":583,"public_recommendation":584,"recommendation":86,"references":585,"cvssv3":209,"epss_score":589,"epss_percentile":590,"cve":591,"in_cisa_catalog":9,"date":593,"software_type":86,"vendor":594,"product":595,"ptt_exploit_capabilities":86},"Provectus kafka-ui versions 0.7.0 through 0.7.2 are vulnerable to code injection in the `\u002Fapi\u002Fsmartfilters\u002Ftestexecutions` endpoint. The `filterCode` parameter is evaluated as a Groovy expression without sandboxing, allowing an unauthenticated attacker to execute arbitrary code and operating-system commands on the host.","Provectus kafka-ui is end-of-life and no patched release exists (0.7.2 is the final version). Migrate to the maintained kafbat\u002Fkafka-ui fork, and in the meantime restrict network access to the interface and place it behind authentication.",[586,587,588],"https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-5562","https:\u002F\u002Fvuldb.com\u002F?id.355332","https:\u002F\u002Fgithub.com\u002Fprovectus\u002Fkafka-ui",0.0062,0.47841,[592],"CVE-2026-5562","2026-04-05T00:00:00Z","provectus","kafka-ui","NETSCAN-NUCLEI-CVE-CVE-2026-5562","Provectus kafka-ui \u003C=0.7.2 - Remote Code Execution","2026-09-14T00:00:00Z",{"id":600,"detectable_with":601,"vuln_details":604,"vuln_id":618,"name":619,"published":598,"updated":86},29711,{"tool":602,"engine":603},{"id":92,"name":93},{"id":95,"name":96},{"id":600,"codename":86,"description":86,"severity":150,"risk_description":250,"public_description":605,"public_recommendation":606,"recommendation":86,"references":607,"cvssv3":160,"epss_score":613,"epss_percentile":614,"cve":615,"in_cisa_catalog":49,"date":418,"software_type":86,"vendor":617,"product":617,"ptt_exploit_capabilities":86},"GitLab CE\u002FEE contains an unauthenticated arbitrary file read. Workhorse, the reverse proxy in front of Rails, matches upload routes using EscapedPath() and path.Clean without decoding percent sequences, while Puma decodes them before routing to Grape. Appending a trailing slash to commits or percent-encoding a static path segment as %63ommits therefore bypasses Workhorse upload route rewriting, and Rails reaches file_params_from_body_upload() which opens the path given in the file.path parameter before authenticate! is enforced. On the application\u002Fx-www-form-urlencoded branch the file bytes are handed to Rack::Utils.parse_nested_query, and any invalid percent sequence raises an ArgumentError whose message is interpolated into the HTTP 400 response body, disclosing file content to an unauthenticated caller.","Upgrade GitLab CE\u002FEE to 19.1.8, 19.2.6, or 19.3.2 or later. The fix moves authenticate! ahead of file processing and stops accepting raw file.path and file.size parameters from untrusted clients.",[608,609,610,611,612],"https:\u002F\u002Fabout.gitlab.com\u002Freleases\u002F2026\u002F09\u002F10\u002Fpatch-release-gitlab-19-3-2-released\u002F","https:\u002F\u002Fgitlab.com\u002Fgitlab-org\u002Fgitlab\u002F-\u002Fcommit\u002F0ff7b6b2911723389f2271b10362591b0a69a166","https:\u002F\u002Fgithub.com\u002Fynsmroztas\u002FGitLabSniper","https:\u002F\u002Fgithub.com\u002Fmhtsec\u002FCVE-2026-85706","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-85706",0.11115,0.95684,[616],"CVE-2026-85706","gitlab","NETSCAN-NUCLEI-CVE-CVE-2026-85706","GitLab CE\u002FEE \u003C=19.1.7\u002F19.2.5\u002F19.3.1 - Arbitrary File Read",{"id":621,"detectable_with":622,"vuln_details":625,"vuln_id":640,"name":641,"published":642,"updated":86},29702,{"tool":623,"engine":624},{"id":92,"name":93},{"id":95,"name":96},{"id":621,"codename":86,"description":86,"severity":150,"risk_description":626,"public_description":627,"public_recommendation":628,"recommendation":86,"references":629,"cvssv3":459,"epss_score":633,"epss_percentile":634,"cve":635,"in_cisa_catalog":9,"date":637,"software_type":86,"vendor":638,"product":639,"ptt_exploit_capabilities":86},"Anonymous attackers can reset email and password of the lowest-id activated user, gaining full access including administrator privileges.","FreeScout prior to 1.8.224 contains an authentication bypass caused by improper invite_hash handling and decryption failure in user setup endpoint, letting anonymous attackers reset credentials and log in as the lowest-id activated user, exploit requires no authentication.","Upgrade to version 1.8.224 or later.",[630,631,632],"https:\u002F\u002Fgithub.com\u002Ffreescout-help-desk\u002Ffreescout\u002Fsecurity\u002Fadvisories\u002FGHSA-jqj5-r72v-v29g","https:\u002F\u002Fgithub.com\u002Ffreescout-help-desk\u002Ffreescout\u002Fcommit\u002Fc4688c31","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-53595",0.01945,0.7904,[636],"CVE-2026-53595","2026-07-20T00:00:00Z","freescout-help-desk","freescout","NETSCAN-NUCLEI-CVE-CVE-2026-53595","FreeScout \u003C 1.8.224 - Invite Hash Authorization Bypass","2026-09-11T00:00:00Z",{"id":644,"detectable_with":645,"vuln_details":648,"vuln_id":656,"name":657,"published":642,"updated":86},29703,{"tool":646,"engine":647},{"id":92,"name":93},{"id":95,"name":96},{"id":644,"codename":86,"description":86,"severity":101,"risk_description":649,"public_description":650,"public_recommendation":651,"recommendation":86,"references":652,"cvssv3":86,"epss_score":86,"epss_percentile":86,"cve":86,"in_cisa_catalog":9,"date":86,"software_type":86,"vendor":654,"product":655,"ptt_exploit_capabilities":86},"The risk exists that the data is unknowingly exposed to the internet, making it accessible to remote threat actors that can leverage it to attack the target, or the entire company, depending on the sensitivity of the data.","Detects if the logs\u002Fmetrics page of the Apache Livy server is exposed.","We suggest restricting access to the exposed resource.",[653],"https:\u002F\u002Fgithub.com\u002Fapache\u002Flivy","apache","livy","NETSCAN-NUCLEI-EXPOSURES-APACHE-LIVY-LOGS","Apache Livy - Logs Exposed"]