[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"all-banners":3,"SkipToContent_34xgpJIRRkpiT6ls6jE4NHf7VpvQCQBEwi69exi4oT0":44,"FormattedDate_nlZ3SCgIAOZxUx3GS8DuXgatuk5vlGbGS5JQRMv7zI0":51,"FooterNav_JsYsxvLufb1W12aeknKZ89on0MD0bNDTiB5EYxyxmU":58,"FooterSocial_u16tCafBUeGMoDrdLfTINytP2JB5msc6iB3VDUutAoU":64,"$f2r4b9phgo6bha":71,"$f17q7jdn7tll3p":73,"finding-templates-{\"q\":\"\",\"page\":1}":100},[4,15,21,27,33,39],{"title":5,"slug":6,"text":7,"link":8,"external":9,"targets":10,"cta":12,"variant":13,"campaign_id":14},"Compliance - Page Launch - Network Scanner","compliance-pages-launch-network-scanner","Scheduled scans are the spine of every compliance framework. Are you audit-ready?","https:\u002F\u002Fpentest-tools.com\u002Fusage\u002Fcompliance",false,[11],"\u002Fnetwork-vulnerability-scanning\u002Fnetwork-security-scanner-online","Get compliance evidence","secondary","compliance-pages-launch",{"title":16,"slug":17,"text":18,"link":8,"external":9,"targets":19,"cta":12,"variant":13,"campaign_id":14},"Compliance - Page Launch - Website Scanner","compliance-pages-launch-website-scanner","Authenticated web-app scans show up in SOC 2, NIS2, and CRA Annex I. See why this is crucial for the business.",[20],"\u002Fwebsite-vulnerability-scanning\u002Fwebsite-scanner",{"title":22,"slug":23,"text":24,"link":8,"external":9,"targets":25,"cta":12,"variant":13,"campaign_id":14},"Compliance - Page Launch - Advanced Pentest Reporting","compliance-pages-launch-reporting","Editable DOCX. Immutable PDF. JSON for the GRC tool. See why these formats are on every auditor's checklist.",[26],"\u002Ffeatures\u002Fpentest-reporting",{"title":28,"slug":29,"text":30,"link":8,"external":9,"targets":31,"cta":12,"variant":13,"campaign_id":14},"Compliance - Page Launch - Integrations","compliance-pages-launch-integrations","Vanta, Jira, webhooks - they all route back to DORA, NIS2, SOC 2, ISO 27001, CRA. See why this is crucial for the business.",[32],"\u002Ffeatures\u002Fintegrations",{"title":34,"slug":35,"text":36,"link":8,"external":9,"targets":37,"cta":12,"variant":13,"campaign_id":14},"Compliance - Page Launch - Sniper","compliance-pages-launch-sniper","Five compliance framework pages now reference Sniper as the source of validated exploitability evidence. See them all.",[38],"\u002Fexploit-helpers\u002Fsniper",{"title":40,"slug":14,"text":41,"link":8,"external":9,"targets":42,"cta":12,"variant":13,"campaign_id":14},"Compliance - Page Launch - Homepage","Turn confirmed vulnerabilities into evidence your auditor accepts. Testing requirements for DORA, NIS2, SOC 2, ISO 27001, and CRA.",[43],"\u002F",["Island",45],{"key":46,"params":47,"result":49},"SkipToContent_34xgpJIRRkpiT6ls6jE4NHf7VpvQCQBEwi69exi4oT0",{"props":48},"{}",{"head":50},{},["Island",52],{"key":53,"params":54,"result":56},"FormattedDate_nlZ3SCgIAOZxUx3GS8DuXgatuk5vlGbGS5JQRMv7zI0",{"props":55},"{\"date\":1790079041,\"format\":\"MMMM dd, yyyy\"}",{"head":57},{},["Island",59],{"key":60,"params":61,"result":62},"FooterNav_JsYsxvLufb1W12aeknKZ89on0MD0bNDTiB5EYxyxmU",{"props":48},{"head":63},{},["Island",65],{"key":66,"params":67,"result":69},"FooterSocial_u16tCafBUeGMoDrdLfTINytP2JB5msc6iB3VDUutAoU",{"props":68},"{\"text-color\":\"gray\"}",{"head":70},{},{"count":72},199,{"count":74,"next":75,"previous":76,"results":77},17437,"https:\u002F\u002Fvulndb.pentest-tools.com\u002Fapi\u002Fvulns\u002F?page=2&page_size=1",null,[78],{"id":79,"detectable_with":80,"vuln_details":87,"vuln_id":97,"name":98,"published":99,"updated":76},29753,{"tool":81,"engine":84},{"id":82,"name":83},1,"Network Scanner",{"id":85,"name":86},2,"Nuclei",{"id":79,"epss_score":76,"epss_percentile":76,"in_cisa_catalog":9,"codename":76,"public_description":88,"description":76,"severity":89,"risk_description":90,"public_recommendation":91,"recommendation":76,"references":92,"cvssv3":76,"cve":76,"date":76,"software_type":76,"vendor":96,"product":96,"ptt_exploit_capabilities":76,"category":76},"WordPress contains a client-side selector injection in the theme installer preview route. A crafted URL opened by an authenticated administrator can cause WordPress to automatically install and preview an attacker-selected inactive theme from WordPress.org. The issue can be chained with a separate vulnerability in an installed theme to achieve code execution.","high","The risk exists that an attacker can use the vulnerability identified to perform further attacks on the server.","Update WordPress to 7.1.1 or the corresponding security release for the installed maintenance branch.",[93,94,95],"https:\u002F\u002Fwordpress.org\u002Fnews\u002F2026\u002F09\u002Fwordpress-7-1-1-maintenance-and-security-release\u002F","https:\u002F\u002Fcore.trac.wordpress.org\u002Fchangeset\u002F63664","https:\u002F\u002Fpwn.ai\u002Fblog\u002Fclick2shell","wordpress","NETSCAN-NUCLEI-VULNERABILITIES-WORDPRESS-CLICK2SHELL","WordPress Click2Shell Theme Preview Selector Injection","2026-09-22T00:00:00Z",{"count":74,"next":101,"previous":76,"results":102},"https:\u002F\u002Fvulndb.pentest-tools.com\u002Fapi\u002Fvulns\u002F?limit=25&page=2&search=",[103,125,141,158,182,197,220,226,250,274,298,322,345,367,381,402,413,436,457,481,504,526,545,567,580],{"id":104,"detectable_with":105,"vuln_details":108,"vuln_id":123,"name":124,"published":99,"updated":76},29759,{"tool":106,"engine":107},{"id":82,"name":83},{"id":85,"name":86},{"id":104,"codename":76,"description":76,"severity":89,"risk_description":109,"public_description":110,"public_recommendation":111,"recommendation":76,"references":112,"cvssv3":115,"epss_score":116,"epss_percentile":117,"cve":118,"in_cisa_catalog":9,"date":120,"software_type":76,"vendor":121,"product":122,"ptt_exploit_capabilities":76},"Unauthenticated attackers can access sensitive API keys and configuration data, risking data leakage and unauthorized use of services.","AIWU AI Chatbot & Workflow Automation WordPress plugin \u003C= 1.4.6 contains a sensitive information exposure caused by unauthenticated access to getCurrentTaskResults() method, letting unauthenticated attackers retrieve API keys and configuration data, exploit requires no authentication.","Update to the latest version beyond 1.4.6.",[113,114],"https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-6639","https:\u002F\u002Fwww.wordfence.com\u002Fthreat-intel\u002Fvulnerabilities\u002Fid\u002F247b1921-70a6-4e65-819a-2895bc395e9f?source=cve",7.5,0.00367,0.30468,[119],"CVE-2026-6639","2026-08-05T00:00:00Z","aiwu","ai-copilot-content-generator","NETSCAN-NUCLEI-CVE-CVE-2026-6639","AI Copilot Content Generator \u003C=1.4.6 - Unauthenticated Task Data Exposure",{"id":126,"detectable_with":127,"vuln_details":130,"vuln_id":139,"name":140,"published":99,"updated":76},29755,{"tool":128,"engine":129},{"id":82,"name":83},{"id":85,"name":86},{"id":126,"codename":76,"description":76,"severity":131,"risk_description":132,"public_description":133,"public_recommendation":134,"recommendation":76,"references":135,"cvssv3":76,"epss_score":76,"epss_percentile":76,"cve":76,"in_cisa_catalog":9,"date":76,"software_type":76,"vendor":76,"product":76,"ptt_exploit_capabilities":76},"medium","The risk exists that a remote attacker might leverage the misconfigurations in order to compromise the target.","The OpenID Connect discovery document advertises \"none\" among its id_token_signing_alg_values_supported, meaning the authorization server is willing to issue ID tokens with no signature. A relying party that accepts such a token cannot verify its integrity, enabling JWT \"alg:none\" forgery and authentication bypass. The \"none\" algorithm should never be offered for ID tokens in production.","We recommend you to analyze if this resource should be available or not.",[136,137,138],"https:\u002F\u002Fopenid.net\u002Fspecs\u002Fopenid-connect-discovery-1_0.html","https:\u002F\u002Fdatatracker.ietf.org\u002Fdoc\u002Fhtml\u002Frfc7518#section-3.6","https:\u002F\u002Fdatatracker.ietf.org\u002Fdoc\u002Fhtml\u002Fdraft-ietf-oauth-security-topics","NETSCAN-NUCLEI-MISCONFIGURATION-OIDC-SIGNING-ALG-NONE-SUPPORTED","OpenID Connect - Unsigned (alg none) ID Token Supported",{"id":142,"detectable_with":143,"vuln_details":146,"vuln_id":156,"name":157,"published":99,"updated":76},29754,{"tool":144,"engine":145},{"id":82,"name":83},{"id":85,"name":86},{"id":142,"codename":76,"description":76,"severity":131,"risk_description":147,"public_description":148,"public_recommendation":149,"recommendation":76,"references":150,"cvssv3":76,"epss_score":76,"epss_percentile":76,"cve":76,"in_cisa_catalog":9,"date":76,"software_type":76,"vendor":154,"product":155,"ptt_exploit_capabilities":76},"The risk exists that the data is unknowingly exposed to the internet, making it accessible to remote threat actors that can leverage it to attack the target, or the entire company, depending on the sensitivity of the data.","Exposed PowerDNS Authoritative Server monitor allows unauthenticated access to operational stats, aiding reconnaissance but not zone takeover.","Restrict monitor to localhost, use webserver-allow-from, webserver-password, or firewall to block port 8081.",[151,152,153],"https:\u002F\u002Fdocs.powerdns.com\u002Fauthoritative\u002Fhttp-api\u002Findex.html","https:\u002F\u002Fdoc.powerdns.com\u002Fmd\u002Fcommon\u002Flogging\u002F","https:\u002F\u002Fwww.powerdns.com\u002Fpowerdns-authoritative-server","powerdns","authoritative_server","NETSCAN-NUCLEI-EXPOSURES-POWERDNS-MONITOR-EXPOSURE","PowerDNS Authoritative Server Monitor - Unauthenticated Exposure",{"id":159,"detectable_with":160,"vuln_details":163,"vuln_id":180,"name":181,"published":99,"updated":76},29760,{"tool":161,"engine":162},{"id":82,"name":83},{"id":85,"name":86},{"id":159,"codename":76,"description":76,"severity":164,"risk_description":165,"public_description":166,"public_recommendation":167,"recommendation":76,"references":168,"cvssv3":173,"epss_score":174,"epss_percentile":175,"cve":176,"in_cisa_catalog":9,"date":178,"software_type":76,"vendor":179,"product":179,"ptt_exploit_capabilities":76},"critical","Attackers can escalate their privileges, potentially gaining unauthorized access or control over the application.","Hippoo Mobile App for WooCommerce \u003C= 1.9.4 contains a broken access control vulnerability caused by incorrect privilege assignment, letting attackers escalate their privileges, exploit requires no special conditions.","Update to the latest version.",[169,170,171,172],"https:\u002F\u002Fpatchstack.com\u002Fdatabase\u002Fwordpress\u002Fplugin\u002Fhippoo\u002Fvulnerability\u002Fwordpress-hippoo-mobile-app-for-woocommerce-plugin-1-9-4-privilege-escalation-vulnerability","https:\u002F\u002Fgithub.com\u002Fadvisories\u002FGHSA-mh6m-7983-2r5w","https:\u002F\u002Fwordpress.org\u002Fplugins\u002Fhippoo\u002F","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-49060",9.8,0.00514,0.42604,[177],"CVE-2026-49060","2026-06-11T00:00:00Z","hippoo","NETSCAN-NUCLEI-CVE-CVE-2026-49060","Hippoo Mobile App for WooCommerce - Broken Access Control",{"id":183,"detectable_with":184,"vuln_details":187,"vuln_id":195,"name":196,"published":99,"updated":76},29756,{"tool":185,"engine":186},{"id":82,"name":83},{"id":85,"name":86},{"id":183,"codename":76,"description":76,"severity":131,"risk_description":147,"public_description":188,"public_recommendation":189,"recommendation":76,"references":190,"cvssv3":76,"epss_score":76,"epss_percentile":76,"cve":76,"in_cisa_catalog":9,"date":76,"software_type":76,"vendor":194,"product":194,"ptt_exploit_capabilities":76},"Qdrant ships with no API key configured. When service.api_key is unset, the internal \u002Ftelemetry endpoint answers unauthenticated requests and returns the instance UUID, the running Qdrant version, the number of collections, the cluster configuration, and per-endpoint REST and gRPC request statistics. Reaching this endpoint without a credential also proves that no API key is enforced on the instance at all, since Qdrant gates \u002Ftelemetry behind the same key as the rest of its REST API.","Set service.api_key (and read_only_api_key where a read role is needed) so Qdrant enforces authentication on the REST and gRPC APIs, enable TLS, and keep port 6333 behind an authenticated network boundary rather than on a public interface.",[191,192,193],"https:\u002F\u002Fqdrant.tech\u002Fdocumentation\u002Fguides\u002Fsecurity\u002F","https:\u002F\u002Fapi.qdrant.tech\u002Fapi-reference\u002Fservice\u002Ftelemetry","https:\u002F\u002Fgithub.com\u002Fqdrant\u002Fqdrant","qdrant","NETSCAN-NUCLEI-EXPOSURES-QDRANT-TELEMETRY-EXPOSURE","Qdrant - Telemetry Exposure",{"id":198,"detectable_with":199,"vuln_details":202,"vuln_id":218,"name":219,"published":99,"updated":76},29758,{"tool":200,"engine":201},{"id":82,"name":83},{"id":85,"name":86},{"id":198,"codename":76,"description":76,"severity":164,"risk_description":203,"public_description":204,"public_recommendation":205,"recommendation":76,"references":206,"cvssv3":211,"epss_score":212,"epss_percentile":213,"cve":214,"in_cisa_catalog":9,"date":216,"software_type":76,"vendor":217,"product":217,"ptt_exploit_capabilities":76},"An unauthenticated attacker can recover the full admin email address and password-reset token, enabling direct account takeover without any existing credentials.","Strapi versions starting in 4.0.0 and prior to 5.37.0 did not sufficiently sanitize query parameters when filtering content via relational fields. An attacker could use the `where` query parameter on any publicly-accessible content-type with an `updatedBy` field to perform a boolean-oracle attack against private fields on the joined admin_users table, including the resetPasswordToken field, enabling full administrative account takeover without authentication.","Upgrade Strapi to version 5.37.0 or later. The patch introduces explicit query-parameter sanitization via strictParam, addQueryParams, and addBodyParams primitives that reject operator chains traversing into restricted relational targets before reaching the database.",[207,208,209,210],"https:\u002F\u002Fgithub.com\u002Fstrapi\u002Fstrapi\u002Fsecurity\u002Fadvisories","https:\u002F\u002Fbishopfox.com\u002Fblog\u002Fcve-2026-27886-unauthenticated-boolean-oracle-exfiltration-of-administrator-secrets-in-strapi","https:\u002F\u002Fgithub.com\u002FBishopFox\u002FCVE-2026-27886-check","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-27886",9.2,0.00612,0.4766,[215],"CVE-2026-27886","2026-05-14T00:00:00Z","strapi","NETSCAN-NUCLEI-CVE-CVE-2026-27886","Strapi \u003C=5.36.x - Admin Credential Enumeration",{"id":79,"detectable_with":221,"vuln_details":224,"vuln_id":97,"name":98,"published":99,"updated":76},{"tool":222,"engine":223},{"id":82,"name":83},{"id":85,"name":86},{"id":79,"codename":76,"description":76,"severity":89,"risk_description":90,"public_description":88,"public_recommendation":91,"recommendation":76,"references":225,"cvssv3":76,"epss_score":76,"epss_percentile":76,"cve":76,"in_cisa_catalog":9,"date":76,"software_type":76,"vendor":96,"product":96,"ptt_exploit_capabilities":76},[93,94,95],{"id":227,"detectable_with":228,"vuln_details":231,"vuln_id":248,"name":249,"published":99,"updated":76},29757,{"tool":229,"engine":230},{"id":82,"name":83},{"id":85,"name":86},{"id":227,"codename":76,"description":76,"severity":89,"risk_description":232,"public_description":233,"public_recommendation":234,"recommendation":76,"references":235,"cvssv3":240,"epss_score":241,"epss_percentile":242,"cve":243,"in_cisa_catalog":9,"date":245,"software_type":76,"vendor":246,"product":247,"ptt_exploit_capabilities":76},"The risk exists that a remote unauthenticated attacker could exploit this vulnerability to read sensitive information from arbitrary files located on the file system of the server.","Cockpit CMS through 2.14.0 contains a path traversal and local file inclusion (LFI) vulnerability when executed under PHP's built-in CLI server (PHP_SAPI == 'cli-server') or non-normalizing reverse proxies. The application fails to sanitize dot-dot sequences in PATH_INFO routes starting with '\u002F:' and containing '\u002Fstorage\u002F'. Unauthenticated remote attackers can traverse outside the designated directory to read arbitrary system files.","Upgrade to Cockpit CMS version 2.14.1 or higher.",[236,237,238,239],"https:\u002F\u002Fwww.cve.org\u002FCVERecord?id=CVE-2026-58467","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-58467","https:\u002F\u002Fgithub.com\u002Fcockpit-hq\u002Fcockpit\u002Fcompare\u002F2.14.0...2.14.1","https:\u002F\u002Fgithub.com\u002Fgeo-chen\u002Foss\u002Fblob\u002Fmain\u002Fcockpit.md",8.2,0.00522,0.43133,[244],"CVE-2026-58467","2026-07-02T00:00:00Z","cockpit-hq","cockpit","NETSCAN-NUCLEI-CVE-CVE-2026-58467","Cockpit CMS \u003C= 2.14.0 - Path Traversal \u002F Local File Inclusion",{"id":251,"detectable_with":252,"vuln_details":255,"vuln_id":272,"name":273,"published":99,"updated":76},29761,{"tool":253,"engine":254},{"id":82,"name":83},{"id":85,"name":86},{"id":251,"codename":76,"description":76,"severity":89,"risk_description":256,"public_description":257,"public_recommendation":258,"recommendation":76,"references":259,"cvssv3":264,"epss_score":265,"epss_percentile":266,"cve":267,"in_cisa_catalog":9,"date":269,"software_type":76,"vendor":270,"product":271,"ptt_exploit_capabilities":76},"Unauthenticated attackers gain full WordPress administrator access via forged Bearer token, enabling arbitrary REST API operations — user creation, plugin upload, theme editor write, and persistent backdoor installation (complete site takeover \u002F RCE).","Newfold Digital WordPress plugins bundling wp-module-data \u003C=2.9.4 allow unauthenticated attackers to forge a valid Bearer token and gain WordPress administrator access. The authenticate() method (hooked on rest_authentication_errors) computes: token = sha256(sha256(wp_json_encode({method,url,body,timestamp})) + sha256(strrev(get_auth_token()))) On sites not connected to Hiive, get_auth_token() returns false; PHP coerces strrev(false) to strrev('') = '', so the HMAC salt collapses to the public constant sha256('') = e3b0c44... All other inputs are attacker-controlled, enabling offline token forgery without any secret knowledge.","Update to patched versions: Bluehost >=4.19.1, HostGator >=3.2.1, Web >=2.3.6, Crazy Domains >=2.5.3, or update wp-module-data to >=2.9.8.",[260,261,262,263],"https:\u002F\u002Fwww.wordfence.com\u002Fthreat-intel\u002Fvulnerabilities\u002Fid\u002F3ee369c0-0d7c-4142-b3ba-a518288647ba","https:\u002F\u002Fgithub.com\u002FWayang1337\u002FCVE-2026-80099","https:\u002F\u002Fplugins.trac.wordpress.org\u002Fbrowser\u002Fwp-module-data\u002Ftrunk\u002Fincludes\u002FData.php","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-80099",8.8,0.00508,0.42257,[268],"CVE-2026-80099","2026-09-09T00:00:00Z","newfold","wp-module-data,bluehost-wordpress-plugin,hostgator,wp-plugin-web,crazy-domains","NETSCAN-NUCLEI-CVE-CVE-2026-80099","Newfold WordPress Plugins - Unauthenticated Admin Bypass via Empty HMAC Secret",{"id":275,"detectable_with":276,"vuln_details":279,"vuln_id":295,"name":296,"published":297,"updated":76},29752,{"tool":277,"engine":278},{"id":82,"name":83},{"id":85,"name":86},{"id":275,"codename":76,"description":76,"severity":164,"risk_description":280,"public_description":281,"public_recommendation":282,"recommendation":76,"references":283,"cvssv3":173,"epss_score":288,"epss_percentile":289,"cve":290,"in_cisa_catalog":9,"date":292,"software_type":76,"vendor":293,"product":294,"ptt_exploit_capabilities":76},"The risk exists that a remote unauthenticated attacker can fully compromise the server to steal confidential information, install ransomware, or pivot to the internal network.","Gravity Forms WordPress plugin version 3.1.0.4 and earlier contains an unauthenticated arbitrary file upload vulnerability caused by bypassing extension validation in hidden file upload fields. Unauthenticated attackers can upload any file type including PHP when a form has a File Upload field configured with Hidden visibility. The bypass works because the server-side extension validation is skipped for fields with gfield_visibility_hidden CSS class.","Update Gravity Forms to version 3.1.1 or later.",[284,285,286,287],"https:\u002F\u002Fgithub.com\u002Fmurrez\u002FCVE-2026-84434","https:\u002F\u002Fpatchstack.com\u002Fdatabase\u002Fwordpress\u002Fplugin\u002Fgravityforms\u002Fvulnerability\u002Fwordpress-gravity-forms-plugin-3-1-0-4-unauthenticated-arbitrary-file-upload-via-hidden-file-upload-field-vulnerability","https:\u002F\u002Fwww.wordfence.com\u002Fthreat-intel\u002Fvulnerabilities\u002Fid\u002F787e22a9-329b-4e71-bc2a-4f5524fc9356","https:\u002F\u002Fdocs.gravityforms.com\u002Fgravityforms-change-log\u002F",0.00697,0.51214,[291],"CVE-2026-84434","2026-09-19T00:00:00Z","rocketgenius","gravityforms","NETSCAN-NUCLEI-CVE-CVE-2026-84434","WordPress Gravity Forms Plugin \u003C=3.1.0.4 - Unauthenticated Arbitrary File Upload","2026-09-21T00:00:00Z",{"id":299,"detectable_with":300,"vuln_details":303,"vuln_id":320,"name":321,"published":292,"updated":76},29750,{"tool":301,"engine":302},{"id":82,"name":83},{"id":85,"name":86},{"id":299,"codename":76,"description":76,"severity":164,"risk_description":304,"public_description":305,"public_recommendation":306,"recommendation":76,"references":307,"cvssv3":312,"epss_score":313,"epss_percentile":314,"cve":315,"in_cisa_catalog":9,"date":317,"software_type":76,"vendor":318,"product":319,"ptt_exploit_capabilities":76},"Remote unauthenticated attackers reach the full Argo CD tool surface with the operator's stored API token. Applications can be created pointing at attacker-controlled repositories and synced, which executes hostile manifests in the managed cluster under Argo CD's permissive default project.","argocd-mcp before 0.9.0 binds its MCP HTTP listener to all interfaces without requiring authentication. A remote unauthenticated attacker can initialize an MCP session, complete the handshake, and enumerate or invoke the full Argo CD tool surface using the operator's stored API token.","Upgrade to argocd-mcp 0.9.0 and set MCP_AUTH_TOKEN so inbound callers must present an Authorization bearer header. Keep --bind-address on 127.0.0.1 unless an external auth layer is in front of the listener, and do not use --allow-unauthenticated to restore a wide bind.",[308,309,310,311],"https:\u002F\u002Fgithub.com\u002Fargoproj-labs\u002Fmcp-for-argocd\u002Fsecurity\u002Fadvisories\u002FGHSA-rp45-5x3v-48mr","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-82456","https:\u002F\u002Fwww.vulncheck.com\u002Fadvisories\u002Fargocd-mcp-0.8.0-authentication-bypass-via-unauthenticated-http","https:\u002F\u002Fgithub.com\u002Fargoproj-labs\u002Fmcp-for-argocd\u002Freleases",10,0.01391,0.70707,[316],"CVE-2026-82456","2026-08-29T00:00:00Z","argoproj-labs","mcp-for-argocd","NETSCAN-NUCLEI-CVE-CVE-2026-82456","argocd-mcp 0.8.0 - Unauthenticated MCP Session and Tool Access",{"id":323,"detectable_with":324,"vuln_details":327,"vuln_id":343,"name":344,"published":292,"updated":76},29751,{"tool":325,"engine":326},{"id":82,"name":83},{"id":85,"name":86},{"id":323,"codename":76,"description":76,"severity":131,"risk_description":328,"public_description":329,"public_recommendation":330,"recommendation":76,"references":331,"cvssv3":336,"epss_score":337,"epss_percentile":338,"cve":339,"in_cisa_catalog":9,"date":341,"software_type":76,"vendor":342,"product":342,"ptt_exploit_capabilities":76},"Attackers can execute JavaScript in victim's browser to steal authentication tokens, leading to account compromise.","Yamcs \u003C 5.9.4 contains a stored XSS caused by inadequate HTML escaping of attacker-controlled redirect_uri parameter in authorization template, letting attackers execute JavaScript to steal authentication data, exploit requires user to open crafted URL.","Update to version 5.9.4 or later.",[332,333,334,335],"https:\u002F\u002Fgithub.com\u002Fyamcs\u002Fyamcs\u002Fsecurity\u002Fadvisories\u002FGHSA-rxpg-wjf8-qv9c","https:\u002F\u002Fgithub.com\u002Fyamcs\u002Fyamcs\u002Fcommit\u002F4d47d5cdcf5d92c2c5bbbc19feada422923332e3","https:\u002F\u002Fgithub.com\u002Fyamcs\u002Fyamcs\u002Freleases\u002Ftag\u002Fyamcs-5.9.4","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-55549",6.5,0.00897,0.57565,[340],"CVE-2026-55549","2026-08-28T00:00:00Z","yamcs","NETSCAN-NUCLEI-CVE-CVE-2026-55549","Yamcs \u003C=5.8.6 - Cross-Site Scripting",{"id":346,"detectable_with":347,"vuln_details":350,"vuln_id":364,"name":365,"published":366,"updated":76},29740,{"tool":348,"engine":349},{"id":82,"name":83},{"id":85,"name":86},{"id":346,"codename":76,"description":76,"severity":164,"risk_description":351,"public_description":352,"public_recommendation":353,"recommendation":76,"references":354,"cvssv3":173,"epss_score":357,"epss_percentile":358,"cve":359,"in_cisa_catalog":9,"date":361,"software_type":76,"vendor":362,"product":363,"ptt_exploit_capabilities":76},"An unauthenticated attacker obtains a superuser access token, granting full control of the Langflow instance including flow creation and execution, which typically leads to remote code execution and access to connected credentials and data sources.","Langflow OSS with default AUTO_LOGIN exposes `\u002Fapi\u002Fv1\u002Fauto_login`, which returns a superuser access token to any unauthenticated request.","Disable AUTO_LOGIN by setting `LANGFLOW_AUTO_LOGIN=false`, configure strong superuser credentials, upgrade to a fixed Langflow release, and restrict network exposure of the management interface.",[355,356],"https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-9103","https:\u002F\u002Fgithub.com\u002Flangflow-ai\u002Flangflow",0.02828,0.85912,[360],"CVE-2026-9103","2026-07-17T00:00:00Z","langflow-ai","langflow","NETSCAN-NUCLEI-CVE-CVE-2026-9103","Langflow OSS - Superuser Token Issuance","2026-09-18T00:00:00Z",{"id":368,"detectable_with":369,"vuln_details":372,"vuln_id":379,"name":380,"published":366,"updated":76},29749,{"tool":370,"engine":371},{"id":82,"name":83},{"id":85,"name":86},{"id":368,"codename":76,"description":76,"severity":89,"risk_description":147,"public_description":373,"public_recommendation":374,"recommendation":76,"references":375,"cvssv3":76,"epss_score":76,"epss_percentile":76,"cve":76,"in_cisa_catalog":9,"date":76,"software_type":76,"vendor":378,"product":378,"ptt_exploit_capabilities":76},"etcd's v2 API is reachable without authentication, exposing the \u002Fv2\u002Fmembers endpoint. This endpoint discloses the full cluster membership list, including each member's name, internal peer URLs, and client URLs, without requiring any credentials.","Disable the deprecated v2 API (etcd 3.4+ defaults to v2 disabled; confirm `--enable-v2=false`), enable client authentication and RBAC, and restrict network access to etcd's client",[376,377],"https:\u002F\u002Fetcd.io\u002Fdocs\u002Fv3.5\u002Fop-guide\u002Fauthentication\u002F","https:\u002F\u002Fetcd.io\u002Fdocs\u002Fv3.5\u002Fop-guide\u002Fsecurity\u002F","etcd","NETSCAN-NUCLEI-EXPOSURES-HTTP-ETCD-UNAUTHENTICATED-RAFT","etcd RAFT Unauthenticated API",{"id":382,"detectable_with":383,"vuln_details":386,"vuln_id":400,"name":401,"published":366,"updated":76},29745,{"tool":384,"engine":385},{"id":82,"name":83},{"id":85,"name":86},{"id":382,"codename":76,"description":76,"severity":164,"risk_description":280,"public_description":387,"public_recommendation":388,"recommendation":76,"references":389,"cvssv3":173,"epss_score":392,"epss_percentile":393,"cve":394,"in_cisa_catalog":396,"date":397,"software_type":76,"vendor":398,"product":399,"ptt_exploit_capabilities":76},"Ivanti Endpoint Manager Mobile contains a code injection vulnerability allowing unauthenticated attackers to execute arbitrary code remotely, exploit requires no authentication.","Update to the latest version of Ivanti Endpoint Manager Mobile.",[390,391],"https:\u002F\u002Fforums.ivanti.com\u002Fs\u002Farticle\u002FSecurity-Advisory-Ivanti-Endpoint-Manager-Mobile-EPMM","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-1340",0.98676,0.99923,[395],"CVE-2026-1340",true,"2026-01-29T00:00:00Z","ivanti","endpoint_manager_mobile","NETSCAN-NUCLEI-CVE-CVE-2026-1340","Ivanti EPMM \u003C 12.8.0.0 - Remote Code Execution",{"id":403,"detectable_with":404,"vuln_details":407,"vuln_id":411,"name":412,"published":366,"updated":76},29746,{"tool":405,"engine":406},{"id":82,"name":83},{"id":85,"name":86},{"id":403,"codename":76,"description":76,"severity":89,"risk_description":147,"public_description":408,"public_recommendation":409,"recommendation":76,"references":410,"cvssv3":76,"epss_score":76,"epss_percentile":76,"cve":76,"in_cisa_catalog":9,"date":76,"software_type":76,"vendor":378,"product":378,"ptt_exploit_capabilities":76},"etcd's v3 API is reachable and authentication is disabled or not configured. With auth disabled, the v3 API grants full read and write access to every key in the store to anyone who can reach it.","Enable etcd client authentication and RBAC (`--client-cert-auth=true` plus `etcdctl auth enable`), and restrict network access to the etcd.",[376,377],"NETSCAN-NUCLEI-EXPOSURES-HTTP-ETCD-UNAUTHENTICATED-API-V3","etcd v3 Unauthenticated API",{"id":414,"detectable_with":415,"vuln_details":418,"vuln_id":434,"name":435,"published":366,"updated":76},29743,{"tool":416,"engine":417},{"id":82,"name":83},{"id":85,"name":86},{"id":414,"codename":76,"description":76,"severity":164,"risk_description":419,"public_description":420,"public_recommendation":421,"recommendation":76,"references":422,"cvssv3":312,"epss_score":427,"epss_percentile":428,"cve":429,"in_cisa_catalog":9,"date":431,"software_type":76,"vendor":432,"product":433,"ptt_exploit_capabilities":76},"Attackers can read and modify database content across all cleartext notebooks, potentially compromising data integrity and confidentiality.","SiYuan before v3.7.3 contains a SQL injection caused by direct concatenation of the keyword parameter in \u002Fapi\u002Ffiletree\u002FsearchDocs endpoint, letting attackers with publish RoleReader token or unauthenticated in publish mode read and modify database content.","Update to version 3.7.3 or later.",[423,424,425,426],"https:\u002F\u002Fgithub.com\u002Fsiyuan-note\u002Fsiyuan\u002Fsecurity\u002Fadvisories\u002FGHSA-33jq-p8c2-q3q4","https:\u002F\u002Fgithub.com\u002Fsiyuan-note\u002Fsiyuan\u002Freleases\u002Ftag\u002Fv3.7.3","https:\u002F\u002Fhub.docker.com\u002Fr\u002Fb3log\u002Fsiyuan\u002Ftags","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-69085",0.00875,0.56955,[430],"CVE-2026-69085","2026-08-03T00:00:00Z","b3log","siyuan","NETSCAN-NUCLEI-CVE-CVE-2026-69085","SiYuan \u003C=3.7.2 - SQL Injection",{"id":437,"detectable_with":438,"vuln_details":441,"vuln_id":455,"name":456,"published":366,"updated":76},29742,{"tool":439,"engine":440},{"id":82,"name":83},{"id":85,"name":86},{"id":437,"codename":76,"description":76,"severity":164,"risk_description":232,"public_description":442,"public_recommendation":443,"recommendation":76,"references":444,"cvssv3":173,"epss_score":449,"epss_percentile":450,"cve":451,"in_cisa_catalog":9,"date":453,"software_type":76,"vendor":454,"product":454,"ptt_exploit_capabilities":76},"TEN Framework 0.11.71 contains unauthenticated arbitrary file read and write vulnerabilities in the TMAN Designer file-content API endpoints, letting attackers read or write arbitrary files and execute code. The exploit requires no authentication.","Update to the latest version of TEN Framework.",[445,446,447,448],"https:\u002F\u002Fwww.vulncheck.com\u002Fadvisories\u002Ften-framework-0.11.71-unauthenticated-file-read-write-via-tman-designer","https:\u002F\u002Fgithub.com\u002FTEN-framework\u002Ften-framework\u002Fissues\u002F2187","https:\u002F\u002Fgithub.com\u002FTEN-framework\u002Ften-framework\u002Fblob\u002F0.11.71\u002Fcore\u002Fsrc\u002Ften_manager\u002Fsrc\u002Fdesigner\u002Ffile_content\u002Fmod.rs","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-85688",0.01469,0.72173,[452],"CVE-2026-85688","2026-09-04T00:00:00Z","ten-framework","NETSCAN-NUCLEI-CVE-CVE-2026-85688","TEN Framework - Arbitrary File Read & Write",{"id":458,"detectable_with":459,"vuln_details":462,"vuln_id":479,"name":480,"published":366,"updated":76},29744,{"tool":460,"engine":461},{"id":82,"name":83},{"id":85,"name":86},{"id":458,"codename":76,"description":76,"severity":164,"risk_description":280,"public_description":463,"public_recommendation":464,"recommendation":76,"references":465,"cvssv3":312,"epss_score":472,"epss_percentile":473,"cve":474,"in_cisa_catalog":396,"date":476,"software_type":76,"vendor":477,"product":478,"ptt_exploit_capabilities":76},"N-able N-central versions before 2026.3.1.14 are vulnerable to pre-authentication remote code execution via static code injection (CWE-96). An unauthenticated attacker with network access to the N-central management interface can execute arbitrary code on the server, potentially compromising every managed endpoint under the platform's control. Huntress confirmed active in-the-wild exploitation. N-able's hosted (NCOD) instances were automatically patched, on-premises deployments require manual upgrade to 2026.3.1.14. The N-central build version is exposed pre-authentication in the login page JavaScript object (ncentralVersion), enabling reliable version-based detection.","Upgrade N-central immediately to version 2026.3.1.14 (Hotfix 4) or later. Direct upgrade paths exist from builds 2025.4, 2026.1, 2026.2, 2026.3, and all 2026.3.1 hotfixes. Additionally restrict inbound access to N-central with IP allowlisting or VPN, audit N-central user accounts for unauthorized accounts (especially .invalid emails), and review appliance logs for evidence of pre-exploitation reconnaissance.",[466,467,468,469,470,471],"https:\u002F\u002Fme.n-able.com\u002Fs\u002Fsecurity-advisory\u002FaArVy00","https:\u002F\u002Fwww.huntress.com\u002Fblog\u002Fn-able-vulnerability-exploitation","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-86218","https:\u002F\u002Fwww.bleepingcomputer.com\u002Fnews\u002Fsecurity\u002Fn-able-patches-max-severity-n-central-flaw-amid-ongoing-attacks\u002F","https:\u002F\u002Fforkast.news\u002Fn-able-n-central-cvss-10-0-pre-auth-rce-marks-third-attack-wave-in-six-weeks\u002F","https:\u002F\u002Fcve.mitre.org\u002Fcgi-bin\u002Fcvename.cgi?name=CVE-2026-86218",0.07494,0.94295,[475],"CVE-2026-86218","2026-09-06T00:00:00Z","n-able","n-central","NETSCAN-NUCLEI-CVE-CVE-2026-86218","N-able N-central \u003C2026.3.1.14 - Pre-Authentication Remote Code Execution",{"id":482,"detectable_with":483,"vuln_details":486,"vuln_id":502,"name":503,"published":366,"updated":76},29741,{"tool":484,"engine":485},{"id":82,"name":83},{"id":85,"name":86},{"id":482,"codename":76,"description":76,"severity":164,"risk_description":280,"public_description":487,"public_recommendation":488,"recommendation":76,"references":489,"cvssv3":173,"epss_score":495,"epss_percentile":496,"cve":497,"in_cisa_catalog":9,"date":499,"software_type":76,"vendor":500,"product":501,"ptt_exploit_capabilities":76},"The org.h2.util.JdbcUtils.getConnection method of the H2 database takes as parameters the class name of the driver and URL of the database. An attacker may pass a JNDI driver name and a URL leading to a LDAP or RMI servers, causing remote code execution via the H2 web console (versions before 2.0.206 \u002F 1.4.198 with the console enabled).","Upgrade H2 database to version 2.0.206 or later, and disable the web console (spring.h2.console.enabled=false) or restrict access to it.",[490,491,492,493,494],"https:\u002F\u002Fjfrog.com\u002Fblog\u002Fthe-jndi-strikes-back-unauthenticated-rce-in-h2-database-console\u002F","https:\u002F\u002Fgithub.com\u002Fadvisories\u002FGHSA-h376-j262-vhq6","https:\u002F\u002Fgithub.com\u002Fh2database\u002Fh2database\u002Fcommit\u002Fb24aa46f48904ce64443f8f4353d70a2eed09037","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2021-42392","https:\u002F\u002Fgithub.com\u002Fvulhub\u002Fvulhub\u002Ftree\u002Fmaster\u002Fh2database\u002FCVE-2021-42392",0.83176,0.9967,[498],"CVE-2021-42392","2022-01-10T00:00:00Z","h2database","h2","NETSCAN-NUCLEI-CVE-CVE-2021-42392","H2 Database Console - JNDI Injection RCE",{"id":505,"detectable_with":506,"vuln_details":509,"vuln_id":524,"name":525,"published":366,"updated":76},29747,{"tool":507,"engine":508},{"id":82,"name":83},{"id":85,"name":86},{"id":505,"codename":76,"description":76,"severity":89,"risk_description":510,"public_description":511,"public_recommendation":512,"recommendation":76,"references":513,"cvssv3":115,"epss_score":519,"epss_percentile":520,"cve":521,"in_cisa_catalog":396,"date":523,"software_type":76,"vendor":76,"product":76,"ptt_exploit_capabilities":76},"Unauthenticated attackers can access sensitive resources by obtaining internal tokens, potentially leading to information disclosure.","JFrog Artifactory contains an information disclosure caused by returning an internal anonymous-user token to unauthenticated callers when anonymous access is disabled, letting unauthenticated attackers access sensitive resources. The exploit requires anonymous access to be disabled.","Update to the latest version where this issue is fixed.",[514,515,516,517,518],"https:\u002F\u002Fdocs.jfrog.com\u002Freleases\u002Fdocs\u002Fjfrog-security-advisories","https:\u002F\u002Fwww.wiz.io\u002Fblog\u002Fartifactory-under-attack-in-the-wild-exploitation-of-cve-2026-42016-cve-2026-4201","https:\u002F\u002Fgithub.com\u002FBL0odz\u002FJFrog_CVE-2026-65615-ByGLM","https:\u002F\u002Fedrabb.fr\u002Fposts\u002Ffull-chain-preauth-rce-jfrog-artifactory\u002F","https:\u002F\u002Fwww.cisa.gov\u002Fknown-exploited-vulnerabilities-catalog?field_cve=CVE-2026-42018",0.11038,0.95772,[522],"CVE-2026-42018","2026-08-12T00:00:00Z","NETSCAN-NUCLEI-CVE-CVE-2026-42018","JFrog Artifactory - Anonymous Token Disclosure via Trailing Slash Auth Bypass",{"id":527,"detectable_with":528,"vuln_details":531,"vuln_id":543,"name":544,"published":366,"updated":76},29748,{"tool":529,"engine":530},{"id":82,"name":83},{"id":85,"name":86},{"id":527,"codename":76,"description":76,"severity":89,"risk_description":532,"public_description":533,"public_recommendation":534,"recommendation":76,"references":535,"cvssv3":115,"epss_score":538,"epss_percentile":539,"cve":540,"in_cisa_catalog":9,"date":542,"software_type":76,"vendor":76,"product":76,"ptt_exploit_capabilities":76},"Unauthenticated users can access sensitive sales metrics, potentially exposing business-sensitive information.","Gutenberg Essential Blocks WordPress plugin \u003C 6.4.0 contains an information disclosure caused by unrestricted access to a public REST route exposing non-public WooCommerce sales metrics, letting unauthenticated users read product sales data.","Update to version 6.4.0 or later.",[536,537],"https:\u002F\u002Fwpscan.com\u002Fvulnerability\u002F0401a229-9630-49ab-ae4b-53360cf5d109\u002F","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-13153",0.00921,0.5825,[541],"CVE-2026-13153","2026-08-06T00:00:00Z","NETSCAN-NUCLEI-CVE-CVE-2026-13153","Essential Blocks \u003C 6.4.0 - Information Disclosure",{"id":546,"detectable_with":547,"vuln_details":550,"vuln_id":564,"name":565,"published":566,"updated":76},29739,{"tool":548,"engine":549},{"id":82,"name":83},{"id":85,"name":86},{"id":546,"codename":76,"description":76,"severity":164,"risk_description":551,"public_description":552,"public_recommendation":553,"recommendation":76,"references":554,"cvssv3":173,"epss_score":558,"epss_percentile":559,"cve":560,"in_cisa_catalog":9,"date":562,"software_type":76,"vendor":563,"product":563,"ptt_exploit_capabilities":76},"An unauthenticated attacker gains a full administrator session on the WordPress site, allowing complete takeover including plugin\u002Ftheme editing, arbitrary PHP execution, and data theft.","The compromised Advanced Responsive Video Embedder WordPress plugin releases 10.8.7 and 10.8.8 accept a hardcoded token through the `_wplogin` parameter and establish an authenticated administrator session before normal authentication. A single unauthenticated GET request triggers the backdoor. This template only inspects the redirect and session-cookie response and does not perform any administrative action.","Immediately remove the Advanced Responsive Video Embedder plugin versions 10.8.7 and 10.8.8, reinstall a known-clean release, rotate all secrets and passwords, and audit for rogue administrator accounts and web shells created after the backdoor was published.",[555,556,557],"https:\u002F\u002Fwww.wordfence.com\u002Fblog\u002F2026\u002F07\u002Fwordfence-prism-detected-backdoored-wordpress-plugin-within-two-hours-of-it-being-introduced\u002F","https:\u002F\u002Fplugins.trac.wordpress.org\u002Fbrowser\u002Fadvanced-responsive-video-embedder\u002Ftags\u002F10.8.7\u002Fphp\u002Ffn-update-check.php","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-18072",0.03231,0.87701,[561],"CVE-2026-18072","2026-07-29T00:00:00Z","advanced-responsive-video-embedder","NETSCAN-NUCLEI-CVE-CVE-2026-18072","Advanced Responsive Video Embedder 10.8.7\u002F10.8.8 - Hardcoded Backdoor Authentication Bypass","2026-09-17T00:00:00Z",{"id":568,"detectable_with":569,"vuln_details":572,"vuln_id":577,"name":578,"published":579,"updated":76},29736,{"tool":570,"engine":571},{"id":82,"name":83},{"id":85,"name":86},{"id":568,"codename":76,"description":76,"severity":89,"risk_description":147,"public_description":573,"public_recommendation":574,"recommendation":76,"references":575,"cvssv3":76,"epss_score":76,"epss_percentile":76,"cve":76,"in_cisa_catalog":9,"date":76,"software_type":76,"vendor":362,"product":363,"ptt_exploit_capabilities":76},"Langflow instance is exposed without authentication, allowing unauthorized access to custom LLM flows and component node structures.","We suggest restricting access to the exposed resource.",[356,576],"https:\u002F\u002Fdocs.langflow.org\u002F","NETSCAN-NUCLEI-EXPOSURES-LANGFLOW-API-EXPOSURE","Langflow - Unauthenticated API Exposure","2026-09-16T00:00:00Z",{"id":581,"detectable_with":582,"vuln_details":585,"vuln_id":592,"name":593,"published":579,"updated":76},29737,{"tool":583,"engine":584},{"id":82,"name":83},{"id":85,"name":86},{"id":581,"codename":76,"description":76,"severity":89,"risk_description":147,"public_description":586,"public_recommendation":574,"recommendation":76,"references":587,"cvssv3":76,"epss_score":76,"epss_percentile":76,"cve":76,"in_cisa_catalog":9,"date":76,"software_type":76,"vendor":590,"product":591,"ptt_exploit_capabilities":76},"Flowise AI instance is exposed without authentication, allowing unauthorized access to visual LLM chatflows and integration configurations.",[588,589],"https:\u002F\u002Fgithub.com\u002FFlowiseAI\u002FFlowise","https:\u002F\u002Fdocs.flowiseai.com\u002F","flowiseai","flowise","NETSCAN-NUCLEI-EXPOSURES-FLOWISE-CHATFLOWS-EXPOSURE","Flowise AI - Unauthenticated Chatflows API Exposure"]