[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"SkipToContent_34xgpJIRRkpiT6ls6jE4NHf7VpvQCQBEwi69exi4oT0":3,"FooterNav_JsYsxvLufb1W12aeknKZ89on0MD0bNDTiB5EYxyxmU":10,"FooterSocial_u16tCafBUeGMoDrdLfTINytP2JB5msc6iB3VDUutAoU":16,"all-banners":23,"vulnerability-29721":74},["Island",4],{"key":5,"params":6,"result":8},"SkipToContent_34xgpJIRRkpiT6ls6jE4NHf7VpvQCQBEwi69exi4oT0",{"props":7},"{}",{"head":9},{},["Island",11],{"key":12,"params":13,"result":14},"FooterNav_JsYsxvLufb1W12aeknKZ89on0MD0bNDTiB5EYxyxmU",{"props":7},{"head":15},{},["Island",17],{"key":18,"params":19,"result":21},"FooterSocial_u16tCafBUeGMoDrdLfTINytP2JB5msc6iB3VDUutAoU",{"props":20},"{\"text-color\":\"gray\"}",{"head":22},{},[24,35,41,47,53,59,64],{"title":25,"slug":26,"text":27,"link":28,"external":29,"targets":30,"cta":32,"variant":33,"campaign_id":34},"Compliance - Page Launch - Network Scanner","compliance-pages-launch-network-scanner","Scheduled scans are the spine of every compliance framework. Are you audit-ready?","https:\u002F\u002Fpentest-tools.com\u002Fusage\u002Fcompliance",false,[31],"\u002Fnetwork-vulnerability-scanning\u002Fnetwork-security-scanner-online","Get compliance evidence","secondary","compliance-pages-launch",{"title":36,"slug":37,"text":38,"link":28,"external":29,"targets":39,"cta":32,"variant":33,"campaign_id":34},"Compliance - Page Launch - Website Scanner","compliance-pages-launch-website-scanner","Authenticated web-app scans show up in SOC 2, NIS2, and CRA Annex I. See why this is crucial for the business.",[40],"\u002Fwebsite-vulnerability-scanning\u002Fwebsite-scanner",{"title":42,"slug":43,"text":44,"link":28,"external":29,"targets":45,"cta":32,"variant":33,"campaign_id":34},"Compliance - Page Launch - Advanced Pentest Reporting","compliance-pages-launch-reporting","Editable DOCX. Immutable PDF. JSON for the GRC tool. See why these formats are on every auditor's checklist.",[46],"\u002Ffeatures\u002Fpentest-reporting",{"title":48,"slug":49,"text":50,"link":28,"external":29,"targets":51,"cta":32,"variant":33,"campaign_id":34},"Compliance - Page Launch - Integrations","compliance-pages-launch-integrations","Vanta, Jira, webhooks - they all route back to DORA, NIS2, SOC 2, ISO 27001, CRA. See why this is crucial for the business.",[52],"\u002Ffeatures\u002Fintegrations",{"title":54,"slug":55,"text":56,"link":28,"external":29,"targets":57,"cta":32,"variant":33,"campaign_id":34},"Compliance - Page Launch - Sniper","compliance-pages-launch-sniper","Five compliance framework pages now reference Sniper as the source of validated exploitability evidence. See them all.",[58],"\u002Fexploit-helpers\u002Fsniper",{"title":60,"slug":34,"text":61,"link":28,"external":29,"targets":62,"cta":32,"variant":33,"campaign_id":34},"Compliance - Page Launch - Homepage","Turn confirmed vulnerabilities into evidence your auditor accepts. Testing requirements for DORA, NIS2, SOC 2, ISO 27001, and CRA.",[63],"\u002F",{"title":65,"slug":66,"text":67,"link":68,"external":69,"targets":70,"cta":73,"variant":33,"campaign_id":66},"Office Hours #11 - Compliance cycle survey","office-hours-11","[Live Office Hours, Wed Sept 16] Continuous compliance evidence: from automated tools or tired humans?","https:\u002F\u002Fzoom.us\u002Fwebinar\u002Fregister\u002F5117815316917\u002FWN_FLMs2-vyQbCTB67guMJH-Q",true,[71,72],"\u002Finsights\u002Fcompliance-cycles-survey","\u002Finsights","Save your spot",{"id":75,"detectable_with":76,"vuln_details":83,"vuln_id":101,"name":102,"published":103,"updated":84},29721,{"tool":77,"engine":80},{"id":78,"name":79},1,"Network Scanner",{"id":81,"name":82},2,"Nuclei",{"id":75,"codename":84,"description":84,"severity":85,"risk_description":86,"public_description":87,"public_recommendation":88,"recommendation":84,"references":89,"cvssv3":93,"epss_score":94,"epss_percentile":95,"cve":96,"in_cisa_catalog":29,"date":98,"software_type":84,"vendor":99,"product":100,"ptt_exploit_capabilities":84},null,"critical","Malicious websites can perform authenticated API requests to exfiltrate or delete data, leading to data loss and information disclosure.","LightRAG \u003C= 1.5.4 contains a broken access control vulnerability caused by default CORS_ORIGINS=* with allow_credentials=True in lightrag_server.py, letting malicious websites perform authenticated API requests, exploit requires authenticated user.","Update to version 1.5.4 or later.",[90,91,92],"https:\u002F\u002Fgithub.com\u002FHKUDS\u002FLightRAG\u002Fsecurity\u002Fadvisories\u002FGHSA-6x6h-qqr7-855w","https:\u002F\u002Fgithub.com\u002FHKUDS\u002FLightRAG\u002Fcommit\u002F09567a4c983f580050db63569dd477122c058c3d","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-61736",9.3,0.00532,0.4335,[97],"CVE-2026-61736","2026-07-15T00:00:00Z","hkuds","lightrag","NETSCAN-NUCLEI-CVE-CVE-2026-61736","LightRAG \u003C= 1.5.3 - Credentialed CORS Wildcard","2026-09-15T00:00:00Z"]