Vulnerability templates

In addition to query-based vulnerability reporting, runZero natively detects exposures using an embedded version of the open-source Nuclei vulnerability scanner and it’s YAML-based vulnerability check templates. To maintain fast scan times and minimize network disruption, runZero dynamically selects appropriate templates based on the scan’s configured categories and precise asset and service fingerprinting.

The table below lists the templates available for scans. The full set can be found in our nuclei-templates repository.

Current templates

2200 templates, last updated on: 2026-01-15

NameCVEsEnabled bySeverityTemplate Source
.NET Framework - Leaking ObjRefs via HTTP .NET RemotingCVE-2024-29059Identify critical remote vulnerabilitiesHighSource
1Password SCIM Bridge - PanelIdentify web-based control panelsInfoSource
3COM NJ2000 Default CredentialsIdentify default logins in web-based control panelsHighSource
3CX Phone System Management Console - Panel DetectIdentify web-based control panelsInfoSource
3CX Phone System Web Client Management Console - Panel DetectIdentify web-based control panelsInfoSource
3Com Wireless 8760 Dual Radio Default CredentialsIdentify default logins in web-based control panelsHighSource
3ware Controller 3DM2 Default CredentialsIdentify default logins in web-based control panelsHighSource
74cms - ajax_common.php SQL InjectionCVE-2020-22209Identify critical remote vulnerabilitiesCriticalSource
74cms - ajax_officebuilding.php SQL InjectionCVE-2020-22210Identify critical remote vulnerabilitiesCriticalSource
74cms - ajax_street.php 'key' SQL InjectionCVE-2020-22211Identify critical remote vulnerabilitiesCriticalSource
74cms - ajax_street.php 'x' SQL InjectionCVE-2020-22208Identify critical remote vulnerabilitiesCriticalSource
AC Centralized Management System - Default LoginIdentify default logins in web-based control panelsHighSource
AC Smart II - Authentication BypassCVE-2025-10204Identify critical remote vulnerabilitiesHighSource
ACME Challenge Path - Reflected Cross-Site ScriptingIdentify critical remote vulnerabilitiesLowSource
ACTi Video Monitoring Panel - DetectionIdentify web-based control panelsInfoSource
AIC Intelligent Campus System - Password ExposureIdentify critical remote vulnerabilitiesMediumSource
AJ-Report < 1.4.1 - Remote Code ExecutionCVE-2024-7314Identify critical remote vulnerabilitiesCriticalSource
AKHQ Panel - DetectIdentify web-based control panelsInfoSource
AMD Pensando PSM - Default LoginIdentify default logins in web-based control panelsHighSource
AMR Printer Management Dashboard - ExposureIdentify critical remote vulnerabilitiesMediumSource
APC Rack PDU Default LoginIdentify default logins in web-based control panelsHighSource
ARL Default CredentialsIdentify default logins in web-based control panelsHighSource
ARRIS Touchstone Telephony Modem - Panel DetectIdentify web-based control panelsInfoSource
ASUS AiCloud Panel - DetectIdentify web-based control panelsInfoSource
ASUS RT-N16 Default CredentialsIdentify default logins in web-based control panelsHighSource
ASUS WL-500G Default CredentialsIdentify default logins in web-based control panelsHighSource
ASUS WL-520GU Default CredentialsIdentify default logins in web-based control panelsHighSource
ASUSTOR ADM 3.1.0.RFQ3 - SQL InjectionCVE-2018-11511Identify critical remote vulnerabilitiesCriticalSource
ATutor < 2.2.1 - Cross Site ScriptingCVE-2023-27008Identify critical remote vulnerabilitiesMediumSource
AVM FRITZ!Box 7530 AX - Unauthorized AccessCVE-2024-54767Identify critical remote vulnerabilitiesHighSource
AVTECH DVR - Login Verification Code BypassCVE-2013-4982Identify critical remote vulnerabilitiesLowSource
AVTECH DVR - SSRFIdentify critical remote vulnerabilitiesMediumSource
AVTECH Room Alert Login Panel - DetectIdentify web-based control panelsInfoSource
AVTECH Video Surveillance Product - Authentication BypassIdentify critical remote vulnerabilitiesHighSource
AVTECH Video Surveillance Product - Unauthenticated File DownloadIdentify critical remote vulnerabilitiesHighSource
AWS EC2 Auto Scaling LabIdentify web-based control panelsInfoSource
AWStats <= 7.5 - Full Path DisclosureIdentify critical remote vulnerabilitiesMediumSource
Abandoned Cart Lite for WooCommerce < 5.2.0 - Cross-Site ScriptingCVE-2019-25152Identify critical remote vulnerabilitiesHighSource
Academy LMS 6.2 - SQL InjectionCVE-2023-4974Identify critical remote vulnerabilitiesMediumSource
AceNet AceReporter Report Panel - DetectIdentify web-based control panelsInfoSource
Ackee Panel - DetectIdentify web-based control panelsInfoSource
Acrolinx DashboardIdentify web-based control panelsInfoSource
Actifio Resource Center - PanelIdentify web-based control panelsInfoSource
Acunetix Login Panel - DetectIdentify web-based control panelsInfoSource
AdGuard Panel - DetectIdentify web-based control panelsInfoSource
Adapt Authoring Tool - PanelIdentify web-based control panelsInfoSource
AddOnFinance Portal - DetectIdentify web-based control panelsInfoSource
Adfinity Login Panel - DetectIdentify web-based control panelsInfoSource
Adminer <4.7.9 - Server-Side Request ForgeryCVE-2021-21311Identify critical remote vulnerabilitiesHighSource
Adminer <=4.8.0 - Cross-Site ScriptingCVE-2021-29625Identify critical remote vulnerabilitiesHighSource
Adminer Default CredentialsIdentify default logins in web-based control panelsHighSource
Adminer Login Panel - DetectIdentify web-based control panelsInfoSource
Adminer Login Panel - DetectIdentify web-based control panelsInfoSource
Adobe AEM CRX Package Manager - Panel DetectIdentify web-based control panelsInfoSource
Adobe AEM Default CredentialsIdentify default logins in web-based control panelsHighSource
Adobe AEM JCR Compare ExposureIdentify critical remote vulnerabilitiesMediumSource
Adobe ColdFusion - Access Control BypassCVE-2023-38205Identify critical remote vulnerabilitiesHighSource
Adobe ColdFusion - Access Control BypassCVE-2023-29298Identify critical remote vulnerabilitiesHighSource
Adobe ColdFusion - Arbitrary File ReadCVE-2024-20767Identify critical remote vulnerabilitiesHighSource
Adobe ColdFusion - Local File ReadCVE-2023-26360Identify critical remote vulnerabilitiesHighSource
Adobe ColdFusion 8.0/8.0.1/9.0/9.0.1 LFICVE-2010-2861Identify critical remote vulnerabilitiesCriticalSource
Adobe ColdFusion Component Browser Login PanelIdentify web-based control panelsInfoSource
Adobe ColdFusion WDDX Deserialization GadgetsCVE-2023-44353Identify critical remote vulnerabilitiesCriticalSource
Adobe Coldfusion - Authentication BypassCVE-2023-26347Identify critical remote vulnerabilitiesHighSource
Adobe Connect < 12.1.5 - Local File DisclosureCVE-2023-22232Identify critical remote vulnerabilitiesMediumSource
Adobe Connect Central Login PanelIdentify web-based control panelsInfoSource
Adobe Experience Manager Felix Console Default CredentialsIdentify default logins in web-based control panelsHighSource
Adobe Experience Manager Login PanelIdentify web-based control panelsInfoSource
Adobe Experience Manager Sling User Login - DetectIdentify web-based control panelsInfoSource
Adobe Media Server Login PanelIdentify web-based control panelsInfoSource
Ads Pro Plugin <= 4.89 - Local File InclusionCVE-2025-4380Identify critical remote vulnerabilitiesCriticalSource
Advanced eMail Solution DEEPMail - PanelIdentify web-based control panelsInfoSource
Advantech R-SeeNet 2.4.12 - OS Command InjectionCVE-2021-21805Identify critical remote vulnerabilitiesCriticalSource
Aerohive NetConfig UIIdentify web-based control panelsInfoSource
Aethra Telecommunications Login - PanelIdentify web-based control panelsInfoSource
Agent-Zero 0.8.0 - 0.9.4 - Arbitrary File DownloadCVE-2025-55523Identify critical remote vulnerabilitiesHighSource
Agentejo Cockpit < 0.11.2 - NoSQL InjectionCVE-2020-35846Identify critical remote vulnerabilitiesCriticalSource
Agentejo Cockpit <0.11.2 - NoSQL InjectionCVE-2020-35847Identify critical remote vulnerabilitiesCriticalSource
Agentejo Cockpit <0.12.0 - NoSQL InjectionCVE-2020-35848Identify critical remote vulnerabilitiesCriticalSource
AirNotifier Login Panel - DetectIdentify web-based control panelsInfoSource
AirOS Panel - DetectIdentify web-based control panelsInfoSource
Airflow Experimental <1.10.11 - REST API Auth BypassCVE-2020-13927Identify critical remote vulnerabilitiesCriticalSource
Akuiteo Login Panel - DetectIdentify web-based control panelsInfoSource
Alamos GmbH Panel - DetectIdentify web-based control panelsInfoSource
Alcatel-Lucent OmniPCX - Remote Command ExecutionCVE-2007-3010Identify critical remote vulnerabilitiesCriticalSource
Alfresco Content App Panel - DetectIdentify web-based control panelsInfoSource
Alibaba Druid Monitor - Default LoginIdentify default logins in web-based control panelsHighSource
Alibaba Nacos - Default LoginIdentify default logins in web-based control panelsHighSource
AlienVault USM Login PanelIdentify web-based control panelsInfoSource
All-in-One WP Migration < 7.87 - Unauthenticated Information DisclosureCVE-2024-8852Identify critical remote vulnerabilitiesMediumSource
Allied Telesis Device GUI Login Panel - DetectIdentify web-based control panelsInfoSource
Allnet Default CredentialsIdentify default logins in web-based control panelsHighSource
AlphaWeb XE Default CredentialsIdentify default logins in web-based control panelsMediumSource
Altenergy Power Control Software - SQL InjectionCVE-2024-11305Identify critical remote vulnerabilitiesMediumSource
AlternC Desktop Panel - DetectIdentify web-based control panelsInfoSource
Ambassador API Gateway Diagnostics - ExposureIdentify critical remote vulnerabilitiesMediumSource
Amcrest LoginIdentify web-based control panelsInfoSource
AmpJuke Default CredentialsIdentify default logins in web-based control panelsHighSource
Ampache Login Panel - DetectIdentify web-based control panelsInfoSource
Anaqua Login - PanelIdentify web-based control panelsInfoSource
Ansible Semaphore Panel DetectIdentify web-based control panelsInfoSource
Ansible Tower - DetectIdentify web-based control panelsInfoSource
AnteeoWMS < v4.7.34 - SQL InjectionCVE-2024-44349Identify critical remote vulnerabilitiesCriticalSource
Anyscale Ray - Remote Code ExecutionCVE-2023-48022Identify critical remote vulnerabilitiesCriticalSource
AnythingLLM - Information DisclosureCVE-2024-6842Identify critical remote vulnerabilitiesHighSource
Apache 2.4.49 - Path Traversal and Remote Code ExecutionCVE-2021-41773Identify critical remote vulnerabilitiesHighSource
Apache 2.4.49/2.4.50 - Path Traversal and Remote Code ExecutionCVE-2021-42013Identify critical remote vulnerabilitiesCriticalSource
Apache APISIX Login Panel - DetectIdentify web-based control panelsInfoSource
Apache ActiveMQ Artemis Console Default LoginIdentify default logins in web-based control panelsHighSource
Apache ActiveMQ Default LoginIdentify default logins in web-based control panelsHighSource
Apache ActiveMQ ExposureIdentify web-based control panelsInfoSource
Apache Airflow <1.10.14 - Authentication BypassCVE-2020-17526Identify critical remote vulnerabilitiesHighSource
Apache Airflow <=1.10.10 - Remote Code ExecutionCVE-2020-11978Identify critical remote vulnerabilitiesHighSource
Apache Airflow Admin Login PanelIdentify web-based control panelsInfoSource
Apache Airflow Default LoginIdentify default logins in web-based control panelsHighSource
Apache Airflow OS Command InjectionCVE-2022-24288Identify critical remote vulnerabilitiesHighSource
Apache Airflow v3 Default LoginIdentify default logins in web-based control panelsHighSource
Apache Ambari Default CredentialsIdentify default logins in web-based control panelsHighSource
Apache Apisix Admin Default CredentialsIdentify default logins in web-based control panelsHighSource
Apache Apollo Default CredentialsIdentify default logins in web-based control panelsHighSource
Apache Apollo Panel - DetectIdentify web-based control panelsInfoSource
Apache CloudStack Default CredentialsIdentify default logins in web-based control panelsHighSource
Apache DolphinScheduler Default CredentialsIdentify default logins in web-based control panelsHighSource
Apache Doris Default CredentialsIdentify default logins in web-based control panelsHighSource
Apache Flink - Local File InclusionCVE-2020-17519Identify critical remote vulnerabilitiesHighSource
Apache HTTP Server - ACL BypassCVE-2024-38473Identify critical remote vulnerabilitiesHighSource
Apache HTTP Server End-of-Life - DetectIdentify web-based control panelsInfoSource
Apache HertzBeat - Default CredentialsIdentify default logins in web-based control panelsHighSource
Apache HugeGraph-Server - Remote Command ExecutionCVE-2024-27348Identify critical remote vulnerabilitiesHighSource
Apache HugeGraph-Server <1.5.0 - Authentication BypassCVE-2024-43441Identify critical remote vulnerabilitiesCriticalSource
Apache JMeter Dashboard Login Panel - DetectIdentify web-based control panelsInfoSource
Apache Kafka Center Default CredentialsIdentify default logins in web-based control panelsHighSource
Apache Kafka Consumer Offset Monitor Panel - DetectIdentify web-based control panelsInfoSource
Apache Kafka Control Center Login Panel - DetectIdentify web-based control panelsInfoSource
Apache Kafka Monitor Login Panel - DetectIdentify web-based control panelsInfoSource
Apache Karaf Default CredentialsIdentify default logins in web-based control panelsHighSource
Apache Mesos - Panel DetectIdentify web-based control panelsInfoSource
Apache NiFi - Information DisclosureCVE-2024-56512Identify critical remote vulnerabilitiesMediumSource
Apache NiFi - Remote Code ExecutionIdentify critical remote vulnerabilitiesCriticalSource
Apache OFBiz - Improper Authorization & Remote Code ExecutionCVE-2024-38856Identify critical remote vulnerabilitiesCriticalSource
Apache OFBiz - XML External Entity InjectionCVE-2011-3600Identify critical remote vulnerabilitiesHighSource
Apache OFBiz Directory Traversal - Remote Code ExecutionCVE-2024-32113Identify critical remote vulnerabilitiesHighSource
Apache OfBiz Default LoginIdentify default logins in web-based control panelsHighSource
Apache Pinot < 1.3.0 - Authentication BypassIdentify critical remote vulnerabilitiesCriticalSource
Apache Ranger Default CredentialsIdentify default logins in web-based control panelsHighSource
Apache RocketMQ Console Panel - DetectIdentify web-based control panelsInfoSource
Apache S2-032 Struts - Remote Code ExecutionCVE-2016-3081Identify critical remote vulnerabilitiesHighSource
Apache ShardingSphere ElasticJob-UI privilege escalationCVE-2022-22733Identify critical remote vulnerabilitiesMediumSource
Apache Solr - Authentication BypassCVE-2024-45216Identify critical remote vulnerabilitiesCriticalSource
Apache Solr - Host Environment Variables Leak via Metrics APICVE-2023-50290Identify critical remote vulnerabilitiesMediumSource
Apache Solr Admin Panel - DetectIdentify web-based control panelsInfoSource
Apache Spark Panel - DetectIdentify web-based control panelsInfoSource
Apache Spark UI - Remote Command InjectionCVE-2022-33891Identify critical remote vulnerabilitiesHighSource
Apache Streampark - Default LoginIdentify default logins in web-based control panelsHighSource
Apache Streampark - DetectIdentify web-based control panelsInfoSource
Apache Struts 2 - DefaultActionMapper Prefixes OGNL Code ExecutionCVE-2013-2251Identify critical remote vulnerabilitiesCriticalSource
Apache Struts 2 - Remote Command ExecutionCVE-2017-5638Identify critical remote vulnerabilitiesCriticalSource
Apache Struts 2.0.0-2.5.25 - Remote Code ExecutionCVE-2020-17530Identify critical remote vulnerabilitiesCriticalSource
Apache Struts <=2.5.20 - Remote Code ExecutionCVE-2019-0230Identify critical remote vulnerabilitiesCriticalSource
Apache Struts2 S2-008 RCECVE-2012-0392Identify critical remote vulnerabilitiesMediumSource
Apache Struts2 S2-012 RCECVE-2013-1965Identify critical remote vulnerabilitiesCriticalSource
Apache Struts2 S2-053 - Remote Code ExecutionCVE-2017-12611Identify critical remote vulnerabilitiesCriticalSource
Apache Struts2 S2-053 - Remote Code ExecutionCVE-2017-9791Identify critical remote vulnerabilitiesCriticalSource
Apache Struts2 S2-057 - Remote Code ExecutionCVE-2018-11776Identify critical remote vulnerabilitiesHighSource
Apache Superset - Authentication BypassCVE-2023-27524Identify critical remote vulnerabilitiesHighSource
Apache Superset Login Panel - DetectIdentify web-based control panelsInfoSource
Apache Tomcat Default CredentialsIdentify default logins in web-based control panelsInfoSource
Apache Tomcat Manager Default CredentialsIdentify default logins in web-based control panelsHighSource
Apache Tomcat Manager Login Panel - DetectIdentify web-based control panelsInfoSource
Apache Tomcat Remote Command ExecutionCVE-2020-9484Identify critical remote vulnerabilitiesHighSource
Apache `mod_proxy_cluster` Cluster Manager Interface - ExposureIdentify web-based control panelsInfoSource
Aperio eSlideManager - PanelIdentify web-based control panelsInfoSource
Apigee Login Panel - DetectIdentify web-based control panelsInfoSource
Apollo Default CredentialsIdentify default logins in web-based control panelsHighSource
Application Management Panel - DetectIdentify web-based control panelsInfoSource
Appsmith User Login - Panel DetectIdentify web-based control panelsInfoSource
Appspace Login Panel - DetectIdentify web-based control panelsInfoSource
Appsuite Login Panel - DetectIdentify web-based control panelsInfoSource
Appwrite Login Panel - DetectIdentify web-based control panelsInfoSource
Aptus Login - Panel DetectIdentify web-based control panelsInfoSource
Aqua Enterprise - Panel DetectIdentify web-based control panelsInfoSource
Aquatronica Controller System <= 5.1.6 - Information DisclosureCVE-2025-25037Identify critical remote vulnerabilitiesHighSource
ArangoDB Web Interface - DetectIdentify web-based control panelsInfoSource
ArcGIS REST Services Directory - DetectIdentify web-based control panelsInfoSource
ArcServe Panel - DetectIdentify web-based control panelsInfoSource
Archibus Web Central Login - Panel DetectIdentify web-based control panelsInfoSource
Arcserve UDP <= 9.0.6034 - Authentication BypassCVE-2023-26258Identify critical remote vulnerabilitiesCriticalSource
Arcserve Unified Data Protection - Authentication BypassCVE-2024-0799Identify critical remote vulnerabilitiesCriticalSource
Argo CD Login PanelIdentify web-based control panelsInfoSource
Argo CD Unauthenticated Access to sensitive settingCVE-2024-37152Identify critical remote vulnerabilitiesMediumSource
Aria2 WebUI - Path traversalCVE-2023-39141Identify critical remote vulnerabilitiesHighSource
Artica Pandora FMS 7.44 - Remote Code ExecutionCVE-2020-13851Identify critical remote vulnerabilitiesHighSource
Aruba Instant - Default LoginIdentify default logins in web-based control panelsHighSource
Astro - Reflected XSS via server islands featureCVE-2025-64764Identify critical remote vulnerabilitiesHighSource
Atarim < 4.2.2 - Sensitive Information ExposureIdentify critical remote vulnerabilitiesHighSource
Atlantis Panel - DetectIdentify web-based control panelsInfoSource
Atlassian Bamboo Login Panel - DetectIdentify web-based control panelsInfoSource
Atlassian Jira Server-Side Template InjectionCVE-2019-11581Identify critical remote vulnerabilitiesCriticalSource
Atlassian Questions For Confluence - Hardcoded CredentialsCVE-2022-26138Identify critical remote vulnerabilitiesCriticalSource
Atom.CMS 2.0 - SQL InjectionCVE-2022-28033Identify critical remote vulnerabilitiesCriticalSource
AudioCodes 310HD, 320HD, 420HD, 430HD & 440HD Default CredentialsIdentify default logins in web-based control panelsHighSource
AudioCodes Device Manager Express - SQL InjectionCVE-2022-24627Identify critical remote vulnerabilitiesCriticalSource
AudioCodes Login - Panel DetectIdentify web-based control panelsInfoSource
Audiobookshelf Login Panel - DetectIdentify web-based control panelsInfoSource
Authelia Panel - DetectIdentify web-based control panelsInfoSource
Authentik Panel - DetectIdentify web-based control panelsInfoSource
AutoSet Page - DetectIdentify web-based control panelsInfoSource
Automation By Autonami < 3.3.0 - SQL InjectionCVE-2024-9186Identify critical remote vulnerabilitiesHighSource
Automatisch Panel - DetectIdentify web-based control panelsInfoSource
AvantFAX Login PanelIdentify web-based control panelsInfoSource
Avatier Password Management PanelIdentify web-based control panelsInfoSource
Aviatrix Cloud Controller PanelIdentify web-based control panelsInfoSource
Avigilon Login Panel - DetectIdentify web-based control panelsInfoSource
Avtech AVN801 Network Camera Admin Panel - DetectIdentify web-based control panelsInfoSource
Axel WebServer - Panel DetectIdentify web-based control panelsInfoSource
Axigen Web Admin DetectionIdentify web-based control panelsInfoSource
Axigen WebMail PanelDetectionIdentify web-based control panelsInfoSource
Axway API Manager Panel - DetectIdentify web-based control panelsInfoSource
Axway SecureTransport Login Panel - DetectIdentify web-based control panelsInfoSource
Axway SecureTransport Web Client Panel - DetectIdentify web-based control panelsInfoSource
Axxon Next Client Login - DetectIdentify web-based control panelsInfoSource
Azkaban Web ClientIdentify web-based control panelsInfoSource
Azkaban Web Client Default CredentialsIdentify default logins in web-based control panelsHighSource
BEdita Login Panel - DetectIdentify web-based control panelsInfoSource
BMC Control-M MFT Login Panel - DetectIdentify web-based control panelsInfoSource
BMC Discovery Login Panel - DetectIdentify web-based control panelsInfoSource
BMC Remedy SSO Login Panel - DetectIdentify web-based control panelsInfoSource
Barco ClickShare Default CredentialsIdentify default logins in web-based control panelsHighSource
Barracuda Message Archiver - Panel DetectIdentify web-based control panelsInfoSource
Batflat CMS Default CredentialsIdentify default logins in web-based control panelsHighSource
Bazarr < 1.4.3 - Arbitrary File ReadIdentify critical remote vulnerabilitiesHighSource
Beego Admin Dashboard Panel- DetectIdentify web-based control panelsMediumSource
Beszel Login Panel - DetectIdentify web-based control panelsInfoSource
Better Search Replace < 1.4.5 - PHP Object InjectionCVE-2023-6933Identify critical remote vulnerabilitiesCriticalSource
BeyondTrust Login Panel - DetectIdentify web-based control panelsInfoSource
BeyondTrust Privileged Remote Access - PanelIdentify web-based control panelsInfoSource
BeyondTrust Remote Support Panel - DetectIdentify web-based control panelsInfoSource
BigAnt Admin Login Panel - DetectIdentify web-based control panelsInfoSource
BigAnt Default CredentialsIdentify default logins in web-based control panelsCriticalSource
BigAnt Server 5.6.06 - Improper Access ControlCVE-2022-23348Identify critical remote vulnerabilitiesMediumSource
BioTime Web Login Panel - DetectIdentify web-based control panelsInfoSource
Bitbucket Panel - DetectIdentify web-based control panelsInfoSource
Bitdefender GravityZone Panel - DetectIdentify web-based control panelsInfoSource
Bitrix Component - Cross-Site ScriptingCVE-2023-1719Identify critical remote vulnerabilitiesHighSource
Bitrix Login PanelIdentify web-based control panelsInfoSource
Bitrix Path DisclosureIdentify critical remote vulnerabilitiesLowSource
Bitrix Site Manager - Log File DisclosureIdentify critical remote vulnerabilitiesMediumSource
Bitwarden Web Vault Login Panel - DetectIdentify web-based control panelsInfoSource
Black Duck Login Panel - DetectIdentify web-based control panelsInfoSource
Blue Iris Login Panel - DetectIdentify web-based control panelsInfoSource
Blue Yonder Panel - DetectIdentify web-based control panelsInfoSource
Bluemind Panel - DetectIdentify web-based control panelsInfoSource
Bonita Default CredentialsIdentify default logins in web-based control panelsHighSource
Bonita Portal Login - DetectIdentify web-based control panelsInfoSource
Bonobo Git Server Login Panel - DetectIdentify web-based control panelsInfoSource
BookStack Login Panel - DetectIdentify web-based control panelsInfoSource
Brother MFC-L9570CDW - Information DisclosureCVE-2024-51977Identify critical remote vulnerabilitiesMediumSource
Browser Configuration "browserconfig.xml" ExposureIdentify critical remote vulnerabilitiesInfoSource
Buddy Panel - DetectIdentify web-based control panelsInfoSource
Buffalo WSR-2533DHPL2 - Path TraversalCVE-2021-20090Identify critical remote vulnerabilitiesCriticalSource
Buildbot Panel - DetectIdentify web-based control panelsInfoSource
Busybox Repository Browser - DetectIdentify web-based control panelsInfoSource
Bylancer Quicklancer 2.4 G - SQL InjectionCVE-2024-7188Identify critical remote vulnerabilitiesHighSource
Bynder Login Panel - DetectIdentify web-based control panelsInfoSource
CAIMORE Gateway Default CredentialsIdentify default logins in web-based control panelsHighSource
CAS Login Panel - DetectIdentify web-based control panelsInfoSource
CData API Server < 23.4.8844 - Path TraversalCVE-2024-31848Identify critical remote vulnerabilitiesCriticalSource
CData Arc < 23.4.8839 - Path TraversalCVE-2024-31850Identify critical remote vulnerabilitiesHighSource
CData Connect < 23.4.8846 - Path TraversalCVE-2024-31849Identify critical remote vulnerabilitiesCriticalSource
CData Sync < 23.4.8843 - Path TraversalCVE-2024-31851Identify critical remote vulnerabilitiesHighSource
CERIO-DT Interface - Command ExecutionIdentify critical remote vulnerabilitiesCriticalSource
CGIT - DetectIdentify web-based control panelsInfoSource
CISCO Expressway Login Panel - DetectIdentify web-based control panelsInfoSource
CRMEB v.5.2.2 - SQL InjectionCVE-2024-36837Identify critical remote vulnerabilitiesHighSource
Cachet <=2.3.18 - SQL InjectionCVE-2021-39165Identify critical remote vulnerabilitiesHighSource
Cacti 1.2.24 - SQL InjectionCVE-2023-39361Identify critical remote vulnerabilitiesCriticalSource
Cacti Login Panel - DetectIdentify web-based control panelsInfoSource
Calibre <= 7.14.0 Arbitrary File ReadIdentify critical remote vulnerabilitiesHighSource
Calibre <= 7.14.0 Remote Code ExecutionCVE-2024-6782Identify critical remote vulnerabilitiesCriticalSource
Camaleon CMS Default CredentialsIdentify default logins in web-based control panelsHighSource
Camaleon CMS Login - PanelIdentify web-based control panelsInfoSource
Camunda Default CredentialsIdentify default logins in web-based control panelsHighSource
Canon Devices - Authentication Bypass in Catwalk ServerCVE-2021-38154Identify critical remote vulnerabilitiesHighSource
Canon R-ADV C3325 Default CredentialsIdentify default logins in web-based control panelsHighSource
Canon iR-ADV Panel - DetectIdentify web-based control panelsInfoSource
Canopy 5.7GHz Access Point Default CredentialsIdentify default logins in web-based control panelsHighSource
Caprover Default CredentialsIdentify default logins in web-based control panelsHighSource
Car Rental Management System 1.0 - Local File InclusionCVE-2020-29227Identify critical remote vulnerabilitiesCriticalSource
Car Rental Management System 1.0 - SQL InjectionCVE-2022-32022Identify critical remote vulnerabilitiesHighSource
CasaOS < 0.4.4 - Authentication Bypass via Internal IPCVE-2023-37265Identify critical remote vulnerabilitiesCriticalSource
CasaOS < 0.4.4 - Authentication Bypass via Random JWT TokenCVE-2023-37266Identify critical remote vulnerabilitiesCriticalSource
CasaOS Login Panel - DetectIdentify web-based control panelsInfoSource
Cascade CMS Panel - DetectIdentify web-based control panelsInfoSource
Casdoor 1.13.0 - Unauthenticated SQL InjectionCVE-2022-24124Identify critical remote vulnerabilitiesHighSource
Casdoor Login Panel - DetectIdentify web-based control panelsInfoSource
CaseManager Login Panel - DetectIdentify web-based control panelsInfoSource
Cassia Bluetooth Gateway Panel - DetectIdentify web-based control panelsInfoSource
Caton Network Manager System Login Panel - DetectIdentify web-based control panelsInfoSource
Cellinx NVT Web Server - Local File DisclosureCVE-2023-23063Identify critical remote vulnerabilitiesHighSource
Celonis Login - PanelIdentify web-based control panelsInfoSource
CentOS EOL - DetectIdentify web-based control panelsInfoSource
CentOS Web Panel - OS Command InjectionCVE-2021-31324Identify critical remote vulnerabilitiesCriticalSource
CentOS Web Panel - SQL InjectionCVE-2021-31316Identify critical remote vulnerabilitiesCriticalSource
CentreStack Login Panel - DetectIdentify web-based control panelsInfoSource
Centreon Login Panel - DetectIdentify web-based control panelsInfoSource
ChanCMS <= 3.3.0 - SQL InjectionCVE-2025-10210Identify critical remote vulnerabilitiesMediumSource
Change Detection - Server Side Template InjectionCVE-2024-32651Identify critical remote vulnerabilitiesCriticalSource
Changedetection.io <= 0.47.4 - Path TraversalCVE-2024-51483Identify critical remote vulnerabilitiesMediumSource
Changedetection.io Panel - DetectIdentify web-based control panelsInfoSource
Changjietong Remote Communication GNRemote.dll - SQL InjectionIdentify critical remote vulnerabilitiesHighSource
Check Point Quantum Gateway - Information DisclosureCVE-2024-24919Identify critical remote vulnerabilitiesHighSource
CheckPoint SSL Network Extender Login Panel - DetectIdentify web-based control panelsInfoSource
Checkmarx Login Panel - DetectIdentify web-based control panelsInfoSource
Checkmk Login Panel - DetectIdentify web-based control panelsInfoSource
Chef Automate < 4.13.295 — SQL InjectionCVE-2025-8868Identify critical remote vulnerabilitiesCriticalSource
Chemotargets Clarity Vista Login Panel - DetectIdentify web-based control panelsInfoSource
ChirpStack Default CredentialsIdentify default logins in web-based control panelsHighSource
ChirpStack LoRaWAN DetectionIdentify web-based control panelsInfoSource
Chronos Panel - DetectIdentify web-based control panelsInfoSource
ChurchCRM - Cross-Site ScriptingIdentify critical remote vulnerabilitiesMediumSource
ChurchCRM - Default LoginIdentify default logins in web-based control panelsHighSource
ChurchCRM Panel - DetectIdentify web-based control panelsInfoSource
Ciphertrust - Default LoginIdentify default logins in web-based control panelsHighSource
Cisco ACE 4710 Device Manager Login Panel - DetectIdentify web-based control panelsInfoSource
Cisco ASA - Local File InclusionCVE-2018-0296Identify critical remote vulnerabilitiesHighSource
Cisco Adaptive Security Appliance (ASA)/Firepower Threat Defense (FTD) - Local File InclusionCVE-2020-3452Identify critical remote vulnerabilitiesHighSource
Cisco Edge 340 Panel - DetectIdentify web-based control panelsInfoSource
Cisco Email Security Appliance - PanelIdentify web-based control panelsInfoSource
Cisco IOS XE - Impant DetectionIdentify critical remote vulnerabilitiesCriticalSource
Cisco IOS XE Web UI - Command InjectionCVE-2023-20198Identify critical remote vulnerabilitiesCriticalSource
Cisco ISE Admin Login Panel - DetectIdentify web-based control panelsInfoSource
Cisco Identity Services Engine Admin Login Panel - DetectIdentify web-based control panelsInfoSource
Cisco Prime Infrastructure Panel - DetectIdentify web-based control panelsInfoSource
Cisco Secure CN Login Panel - DetectIdentify web-based control panelsInfoSource
Cisco Secure Firewall ASA & FTD - Authentication BypassCVE-2025-20362Identify critical remote vulnerabilitiesMediumSource
Cisco ServiceGrid Login Panel - DetectIdentify web-based control panelsInfoSource
Cisco Smart Software Manager On-Prem Panel - DetectIdentify web-based control panelsInfoSource
Cisco Systems Login Panel - DetectIdentify web-based control panelsInfoSource
Cisco TelePresence Login Panel - DetectIdentify web-based control panelsInfoSource
Cisco UCS Manager KVM Login Panel - DetectIdentify web-based control panelsInfoSource
Cisco Unity Connection Panel - DetectIdentify web-based control panelsInfoSource
Cisco Web UI Login - DetectIdentify web-based control panelsInfoSource
Cisco vManage Login Panel - DetectIdentify web-based control panelsInfoSource
Citrix ADC Gateway Login Panel - DetectIdentify web-based control panelsInfoSource
Citrix Bleed - Leaking Session TokensCVE-2023-4966Identify critical remote vulnerabilitiesCriticalSource
Citrix NetScaler Memory Disclosure - CitrixBleed 2Identify critical remote vulnerabilitiesCriticalSource
Citrix Netscaler ADC & Gateway - Out-Of-Bounds Memory ReadCVE-2023-6549Identify critical remote vulnerabilitiesCriticalSource
Citrix SD-WAN and NetScaler SD-WAN - SQL InjectionCVE-2019-12989Identify critical remote vulnerabilitiesCriticalSource
Citrix VPN Panel - DetectIdentify web-based control panelsInfoSource
Claris FileMaker WebDirect Panel - DetectIdentify web-based control panelsInfoSource
CleanWeb Login Panel - DetectIdentify web-based control panelsInfoSource
Clear-Com Core Configuration Manager Panel - DetectIdentify web-based control panelsInfoSource
ClearPass Policy Manager Login Panel - DetectIdentify web-based control panelsInfoSource
Cleo Harmony < 5.8.0.21 - Arbitrary File ReadCVE-2024-50623Identify critical remote vulnerabilitiesHighSource
Cloud OA System - SQL InjectionIdentify critical remote vulnerabilitiesHighSource
CloudPanel Login - DetectIdentify web-based control panelsInfoSource
Cloudera Hue Default CredentialsIdentify default logins in web-based control panelsHighSource
Cloudlog Panel - DetectIdentify web-based control panelsInfoSource
Cloudphysician RADAR Login Panel - DetectIdentify web-based control panelsInfoSource
Cluster Control CMON API - Directory TraversalCVE-2024-41628Identify critical remote vulnerabilitiesHighSource
Cnzxsoft System - Default LoginIdentify default logins in web-based control panelsHighSource
Cobbler 'XML-RPC' - Authentication BypassCVE-2024-47533Identify critical remote vulnerabilitiesCriticalSource
Cobbler - Authentication BypassCVE-2018-1000226Identify critical remote vulnerabilitiesCriticalSource
Cobbler <3.3.0 - Remote Code ExecutionCVE-2021-40323Identify critical remote vulnerabilitiesCriticalSource
Cobbler WebGUI Login Panel - DetectIdentify web-based control panelsInfoSource
Cockpit CMS 0.6.1 - Remote Code ExecutionCVE-2020-35131Identify critical remote vulnerabilitiesCriticalSource
Cockpit Project Login Panel - DetectIdentify web-based control panelsInfoSource
Code-Server Login Panel - DetectIdentify web-based control panelsInfoSource
CodeChecker <= 6.24.1 - Authentication BypassCVE-2024-10081Identify critical remote vulnerabilitiesCriticalSource
Cofense Vision Login Panel - DetectIdentify web-based control panelsInfoSource
ColdFusion Administrator Login Panel - DetectIdentify web-based control panelsInfoSource
Coming Soon & Maintenance < 4.1.7 - Unauthenticated Post/Page AccessCVE-2023-1263Identify critical remote vulnerabilitiesMediumSource
Commvault Web Console Panel - DetectIdentify web-based control panelsInfoSource
Compalex Panel - DetectIdentify web-based control panelsMediumSource
CompleteView Panel - DetectIdentify web-based control panelsInfoSource
Concourse CI Login Panel - DetectIdentify web-based control panelsInfoSource
Concrete5 Install PanelIdentify web-based control panelsCriticalSource
Concrete5 Login Panel - DetectIdentify web-based control panelsInfoSource
ConnectWise Control Remote Support Software Panel - DetectIdentify web-based control panelsInfoSource
ConnectWise ScreenConnect 23.9.7 - Authentication BypassCVE-2024-1709Identify critical remote vulnerabilitiesCriticalSource
Contao Login Panel - DetectIdentify web-based control panelsInfoSource
Content Central Login Panel - DetectIdentify web-based control panelsInfoSource
Contest Gallery < 13.1.0.6 - SQL injectionCVE-2021-24915Identify critical remote vulnerabilitiesCriticalSource
Control Web Panel (CWP) - File InclusionCVE-2021-45467Identify critical remote vulnerabilitiesCriticalSource
Control Web Panel Login Panel - DetectIdentify web-based control panelsInfoSource
CopyParty v1.8.6 - Cross Site ScriptingCVE-2023-38501Identify critical remote vulnerabilitiesMediumSource
Copyparty <= 1.8.2 - Directory TraversalCVE-2023-37474Identify critical remote vulnerabilitiesHighSource
Copyparty <=1.18.6 - Cross-Site ScriptingCVE-2025-54589Identify critical remote vulnerabilitiesMediumSource
Cortex XSOAR Login Panel - DetectIdentify web-based control panelsInfoSource
CouchDB - DetectIdentify web-based control panelsInfoSource
CouchDB Default CredentialsIdentify default logins in web-based control panelsHighSource
CouchDB Erlang Distribution - Remote Command ExecutionCVE-2022-24706Identify critical remote vulnerabilitiesCriticalSource
Cox Business Dominion Gateway Login Panel - DetectIdentify web-based control panelsInfoSource
Craft CMS - Remote Code Execution via Template Path ManipulationCVE-2024-56145Identify critical remote vulnerabilitiesCriticalSource
Craft CMS < 3.3.0 - Server-Side Template InjectionCVE-2020-9757Identify critical remote vulnerabilitiesCriticalSource
Craft CMS <=v3.7.31 - SQL InjectionCVE-2024-37843Identify critical remote vulnerabilitiesCriticalSource
Craft CMS Admin Login Panel - DetectIdentify web-based control panelsInfoSource
CraftCMS - Remote Code ExecutionCVE-2025-32432Identify critical remote vulnerabilitiesCriticalSource
CraftCMS < 4.4.15 - Unauthenticated Remote Code ExecutionCVE-2023-41892Identify critical remote vulnerabilitiesCriticalSource
CraftCMS SEOmatic - Server-Side Template InjectionCVE-2021-41749Identify critical remote vulnerabilitiesCriticalSource
CrafterCMS Engine - Cross-Site ScriptingCVE-2023-4136Identify critical remote vulnerabilitiesHighSource
CrafterCMS Login Panel - DetectIdentify web-based control panelsInfoSource
Creatio Login Panel - DetectIdentify web-based control panelsInfoSource
Crestron Airmedia 2.0 - Default LoginIdentify default logins in web-based control panelsHighSource
Crontab UI - Dashboard ExposureIdentify web-based control panelsHighSource
CrushFTP - Authentication BypassCVE-2025-31161Identify critical remote vulnerabilitiesCriticalSource
CrushFTP Anonymous LoginIdentify default logins in web-based control panelsHighSource
CrushFTP Default CredentialsIdentify default logins in web-based control panelsHighSource
CrushFTP VFS - Sandbox Escape LFRCVE-2024-4040Identify critical remote vulnerabilitiesCriticalSource
CrushFTP WebInterface Panel - DetectIdentify web-based control panelsInfoSource
Crypto <= 2.15 - Authentication BypassCVE-2024-9989Identify critical remote vulnerabilitiesCriticalSource
Cryptobox Panel - DetectIdentify web-based control panelsInfoSource
Cryptocurrency Widgets Pack < 2.0 - SQL InjectionCVE-2022-4059Identify critical remote vulnerabilitiesCriticalSource
CudaTel Login Panel - DetectIdentify web-based control panelsInfoSource
Cvent Login Panel - DetectIdentify web-based control panelsInfoSource
Cyber Chef Panel - DetectIdentify web-based control panelsInfoSource
CyberPanel - Command InjectionCVE-2024-51378Identify critical remote vulnerabilitiesCriticalSource
CyberPower - Missing AuthenticationCVE-2024-32735Identify critical remote vulnerabilitiesCriticalSource
CyberPower - SQL InjectionCVE-2024-32738Identify critical remote vulnerabilitiesHighSource
CyberPower - SQL InjectionCVE-2024-32737Identify critical remote vulnerabilitiesHighSource
CyberPower < v2.8.3 - SQL InjectionCVE-2024-32736Identify critical remote vulnerabilitiesHighSource
CyberPower < v2.8.3 - SQL InjectionCVE-2024-32739Identify critical remote vulnerabilitiesHighSource
Cyberoam SSL VPN Panel - DetectIdentify web-based control panelsInfoSource
Cyberpanel Login Panel - DetectIdentify web-based control panelsInfoSource
D-LINK DNS-320L,DNS-320LW and DNS-327L - Information DisclosureCVE-2024-3274Identify critical remote vulnerabilitiesMediumSource
D-Link AC Centralized Management System Default CredentialsIdentify default logins in web-based control panelsHighSource
D-Link Central WiFi Manager CWM(100) - Remote Code ExecutionCVE-2019-13372Identify critical remote vulnerabilitiesCriticalSource
D-Link D-View 8 v2.0.1.28 - Authentication BypassCVE-2023-5074Identify critical remote vulnerabilitiesCriticalSource
D-Link DAR-8000-10 - Command InjectionCVE-2023-4542Identify critical remote vulnerabilitiesMediumSource
D-Link DIR-605 - Information DisclosureCVE-2021-40655Identify critical remote vulnerabilitiesHighSource
D-Link DIR-615 - Unauthorized AccessCVE-2021-42627Identify critical remote vulnerabilitiesCriticalSource
D-Link DIR-816L - Improper Access ControlCVE-2022-28955Identify critical remote vulnerabilitiesHighSource
D-Link DIR-859 - Information DisclosureCVE-2024-57045Identify critical remote vulnerabilitiesCriticalSource
D-Link DNS-320 - Remote Code ExecutionCVE-2019-16057Identify critical remote vulnerabilitiesCriticalSource
D-Link DSL-2750B Devices Command Injection VulnerabilityCVE-2016-20017Identify critical remote vulnerabilitiesCriticalSource
D-Link NAS - Command Injection via Group ParameterCVE-2024-10915Identify critical remote vulnerabilitiesHighSource
D-Link NAS - Command Injection via Name ParameterCVE-2024-10914Identify critical remote vulnerabilitiesHighSource
D-Link NAS `sc_mgr.cgi` - Remote Code ExecutionIdentify critical remote vulnerabilitiesCriticalSource
D-Link Network Attached Storage - Backdoor AccountCVE-2024-3272Identify critical remote vulnerabilitiesCriticalSource
D-Link Network Attached Storage - Command Injection and Backdoor AccountCVE-2024-3273Identify critical remote vulnerabilitiesCriticalSource
D-Link Routers - Remote Code ExecutionCVE-2019-16920Identify critical remote vulnerabilitiesCriticalSource
DATAGERRY - Improper Access ControlCVE-2024-50967Identify critical remote vulnerabilitiesMediumSource
DATAGERRY - REST API Auth BypassCVE-2024-46627Identify critical remote vulnerabilitiesCriticalSource
DELL iDRAC9 - Default LoginIdentify default logins in web-based control panelsHighSource
DPLUS Dashboard Panel - DetectIdentify web-based control panelsInfoSource
DQS Superadmin Login Panel - DetectIdentify web-based control panelsInfoSource
DVWA - Default LoginIdentify default logins in web-based control panelsCriticalSource
Dahua IPC/VTH/VTO - Authentication BypassCVE-2021-33045Identify critical remote vulnerabilitiesCriticalSource
Dahua IPC/VTH/VTO - Authentication BypassCVE-2021-33044Identify critical remote vulnerabilitiesCriticalSource
Dahua Web Service Panel - DetectIdentify web-based control panelsInfoSource
Danswer - Insecure Direct Object ReferenceCVE-2024-9617Identify critical remote vulnerabilitiesMediumSource
Dapr Dashboard 0.1.0-0.10.0 - Improper Access ControlCVE-2022-38817Identify critical remote vulnerabilitiesHighSource
Darktrace Threat Visualizer Login Panel - DetectIdentify web-based control panelsInfoSource
Dashy Panel - DetectIdentify web-based control panelsInfoSource
Dassault Systèmes DELMIA Apriso (up to 2025) - Insecure DeserializationCVE-2025-5086Identify critical remote vulnerabilitiesCriticalSource
DataEase <= 2.4.1 - Sensitive Information ExposureCVE-2024-30269Identify critical remote vulnerabilitiesMediumSource
DataEase v2.10.2 - JWT Signature Verification BypassCVE-2024-47073Identify critical remote vulnerabilitiesCriticalSource
DataHub Metadata Default CredentialsIdentify default logins in web-based control panelsHighSource
DataTaker DT80 dEX 1.50.012 - Information DisclosureCVE-2017-11165Identify critical remote vulnerabilitiesCriticalSource
Datadog Login Panel - DetectIdentify web-based control panelsInfoSource
Dataease - Login PanelIdentify web-based control panelsInfoSource
Dataease Default CredentialsIdentify default logins in web-based control panelsHighSource
Datagerry Default CredentialsIdentify default logins in web-based control panelsHighSource
Datagerry Panel - DetectIdentify web-based control panelsInfoSource
Dataiku Default CredentialsIdentify default logins in web-based control panelsHighSource
Dataiku Panel - DetectIdentify web-based control panelsInfoSource
Davantis Video Analytics Panel - DetectIdentify web-based control panelsInfoSource
DaybydayCRM Login Panel - DetectIdentify web-based control panelsInfoSource
DbGate Web Client Management - Panel DetectIdentify web-based control panelsInfoSource
Debug Endpoint pprof - Exposure DetectionCVE-2019-11248Identify critical remote vulnerabilitiesHighSource
Dede CMS - SQL InjectionIdentify critical remote vulnerabilitiesCriticalSource
DedeCMS 5.7 - SQL InjectionCVE-2017-17731Identify critical remote vulnerabilitiesCriticalSource
DedeCMS 5.7.87 - Directory TraversalCVE-2023-2059Identify critical remote vulnerabilitiesMediumSource
DedeCMS 5.7SP2 - Cross-Site Request Forgery/Remote Code ExecutionCVE-2018-7700Identify critical remote vulnerabilitiesHighSource
DefectDojo Login Panel - DetectIdentify web-based control panelsInfoSource
Defender Security < 4.1.0 - Protection Bypass (Hidden Login Page)CVE-2023-5089Identify critical remote vulnerabilitiesMediumSource
Dell BMC Panel - DetectIdentify web-based control panelsInfoSource
Dell EMC Avamar and Integrated Data Protection Appliance Installation Manager - Invalid Access ControlCVE-2018-1217Identify critical remote vulnerabilitiesCriticalSource
Dell IDRAC Panel - DetectIdentify web-based control panelsInfoSource
Dell Laser Printer - Unauthenticated Detecthttp-iotHighSource
Dell OpenManage Switch Administrator Login Panel - DetectIdentify web-based control panelsInfoSource
Dell Remote Web Access Panel - DetectIdentify web-based control panelsInfoSource
Dell iDRAC6/7/8 - Default LoginIdentify default logins in web-based control panelsHighSource
Delta Controls Admin Login Panel - DetectIdentify web-based control panelsInfoSource
Deluge - Default LoginIdentify default logins in web-based control panelsHighSource
Deluge WebUI Login Panel - DetectIdentify web-based control panelsInfoSource
Dependency-Track Login - PanelIdentify web-based control panelsInfoSource
Dericam Login Panel - DetectIdentify web-based control panelsInfoSource
Desktop Portal VMware Horizon DaaS Trade PlatformIdentify web-based control panelsInfoSource
DevDojo Voyager - Default loginIdentify default logins in web-based control panelsHighSource
DevDojo Voyager <=1.8.0 - Arbitrary File ReadCVE-2024-55415Identify critical remote vulnerabilitiesMediumSource
Devika - Local File InclusionCVE-2024-5334Identify critical remote vulnerabilitiesHighSource
Devika v1 - Path TraversalCVE-2024-40422Identify critical remote vulnerabilitiesCriticalSource
Dex Authentication - PanelIdentify web-based control panelsInfoSource
Dialogic XMS Admin Console - Default LoginIdentify default logins in web-based control panelsHighSource
Dialogic XMS Admin Console - DetectIdentify web-based control panelsInfoSource
Diced Zipline - DetectIdentify web-based control panelsInfoSource
Dify - User Enumeration via "Account not found" MessageCVE-2025-11750Identify critical remote vulnerabilitiesMediumSource
Dify v1.9.1 - Broken Access ControlCVE-2025-63387Identify critical remote vulnerabilitiesMediumSource
Digital Watchdog - Default LoginIdentify default logins in web-based control panelsHighSource
Digital Watchdog - DetectIdentify web-based control panelsInfoSource
Digital Watchdog DW Spectrum Server 4.2.0.32842 - Information DisclosureCVE-2022-34534Identify critical remote vulnerabilitiesHighSource
DirectAdmin Login Panel - DetectIdentify web-based control panelsInfoSource
Directum Login Panel - DetectIdentify web-based control panelsInfoSource
Discuz Panel - DetectionIdentify web-based control panelsInfoSource
Django QuerySet.order_by - SQL InjectionCVE-2021-35042Identify critical remote vulnerabilitiesCriticalSource
Django SQL InjectionCVE-2020-9402Identify critical remote vulnerabilitiesHighSource
Docassemble - Local File InclusionCVE-2024-27292Identify critical remote vulnerabilitiesHighSource
Docebo eLearning Login Panel - DetectIdentify web-based control panelsInfoSource
Dockge Panel - DetectIdentify web-based control panelsInfoSource
DocuWare - DetectIdentify web-based control panelsInfoSource
Docusaurus Gists Plugin < 4.0.0 - GitHub Personal Access Token ExposureCVE-2025-53624Identify critical remote vulnerabilitiesHighSource
Dokuwiki Login Panel - DetectIdentify web-based control panelsInfoSource
Dolibarr Login Panel - DetectIdentify web-based control panelsInfoSource
Dolibarr Unauthenticated Contacts Database TheftCVE-2023-33568Identify critical remote vulnerabilitiesHighSource
Doris Panel - DetectIdentify web-based control panelsInfoSource
Dotclear Admin Login Panel - DetectIdentify web-based control panelsInfoSource
Dradis Professional Edition Login Panel - DetectIdentify web-based control panelsInfoSource
DragonFly Login - PanelIdentify web-based control panelsInfoSource
Dragonfly - Default LoginIdentify default logins in web-based control panelsHighSource
DrayTek - Remote Code ExecutionCVE-2020-8515Identify critical remote vulnerabilitiesCriticalSource
DrayTek Vigor - Command InjectionCVE-2020-15415Identify critical remote vulnerabilitiesCriticalSource
Draytek VigorConnect 1.6.0-B - Local File InclusionCVE-2021-20123Identify critical remote vulnerabilitiesHighSource
Draytek VigorConnect 6.0-B3 - Local File InclusionCVE-2021-20124Identify critical remote vulnerabilitiesHighSource
Drone CI Login Panel - DetectIdentify web-based control panelsInfoSource
Drupal - Remote Code ExecutionCVE-2019-6340Identify critical remote vulnerabilitiesHighSource
Duomi CMS - SQL InjectionIdentify critical remote vulnerabilitiesCriticalSource
Dynatrace Login Panel - DetectIdentify web-based control panelsInfoSource
DzzOffice Installation Panel - DetectIdentify web-based control panelsHighSource
DzzOffice Login Panel - DetectIdentify web-based control panelsInfoSource
E-mobile Panel - DetectIdentify web-based control panelsInfoSource
EMQX Login Panel - DetectIdentify web-based control panelsInfoSource
EOS HTTP BrowserIdentify web-based control panelsMediumSource
ERPNext - Default LoginIdentify default logins in web-based control panelsHighSource
ESPHome - Authentication BypassCVE-2025-57808Identify critical remote vulnerabilitiesHighSource
ESPHome Login Panel - DetectIdentify web-based control panelsInfoSource
ESXi System Login Panel - DetectIdentify web-based control panelsInfoSource
ETQ Reliance - Reflected XSS via SQLConverterServletCVE-2025-34141Identify critical remote vulnerabilitiesMediumSource
EVSE Web Interface Panel - DetectionIdentify web-based control panelsInfoSource
EVlink City < R8 V3.4.0.1 - Authentication BypassCVE-2021-22707Identify critical remote vulnerabilitiesCriticalSource
EVlink Local Controller - DetectionIdentify web-based control panelsInfoSource
EWM Manager Login Panel - DetectIdentify web-based control panelsInfoSource
Eagle For Apache Kakfa Login - DetectIdentify web-based control panelsInfoSource
EasyCVR video management - Users Information ExposureIdentify critical remote vulnerabilitiesHighSource
EasyJOB Login Panel - DetectIdentify web-based control panelsInfoSource
EasyReport - Default LoginIdentify default logins in web-based control panelsHighSource
EasyVista Login Panel - DetectIdentify web-based control panelsInfoSource
Eclipse BIRT Panel - DetectIdentify web-based control panelsInfoSource
Eclipse Jetty - Directory Listing EnabledIdentify critical remote vulnerabilitiesLowSource
Edito CMS - Sensitive Data LeakCVE-2024-4836Identify critical remote vulnerabilitiesHighSource
EfroTech Timetrax v8.3 - Sql InjectionIdentify critical remote vulnerabilitiesHighSource
Eko Charger Management Console Login Panel - DetectIdentify web-based control panelsInfoSource
Eko Software Update Panel - DetectIdentify web-based control panelsInfoSource
EkoAPI Admin Panel - DetectIdentify web-based control panelsInfoSource
Ektron CMS Login Panel - DetectIdentify web-based control panelsInfoSource
ElasticSearch - Default LoginIdentify default logins in web-based control panelsHighSource
Elber ESE DVB-S/S2 - Authentication BypassCVE-2025-0674Identify critical remote vulnerabilitiesCriticalSource
Electrolink FM/DAB/TV Transmitter - Credentials DisclosureCVE-2025-28228Identify critical remote vulnerabilitiesHighSource
Elemiz Network Manager Login Panel - DetectIdentify web-based control panelsInfoSource
Elestio Memos <= v0.24.0 - Server-Side Request ForgeryCVE-2025-22952Identify critical remote vulnerabilitiesCriticalSource
Email Subscribers by Icegram Express <= 5.7.20 - Unauthenticated SQL Injection via HashCVE-2024-4295Identify critical remote vulnerabilitiesCriticalSource
Emby Login Panel - DetectIdentify web-based control panelsInfoSource
Emby Server - Authentication BypassCVE-2023-33193Identify critical remote vulnerabilitiesCriticalSource
Emerson Network Power IntelliSlot Web Card Panel - DetectIdentify web-based control panelsInfoSource
Emqx - Default LoginIdentify default logins in web-based control panelsHighSource
Enablix Panel - DetectIdentify web-based control panelsInfoSource
Endpoint Protector Login Panel - DetectIdentify web-based control panelsInfoSource
EnjoyRMIS - SQL InjectionIdentify critical remote vulnerabilitiesHighSource
Episerver Login PanelIdentify web-based control panelsInfoSource
Error Log Viewer By WP Guru <= 1.0.1.3 - Missing Authorization to Arbitrary File ReadCVE-2024-12849Identify critical remote vulnerabilitiesHighSource
Esafenet CDG NetSecConfigAjax - Sql InjectionIdentify critical remote vulnerabilitiesHighSource
Esafenet CDG NoticeAjax - Sql InjectionIdentify critical remote vulnerabilitiesHighSource
Eset Protect Login Panel - DetectIdentify web-based control panelsInfoSource
Eslint Ignore File ExposureIdentify critical remote vulnerabilitiesLowSource
Espec Web Controller - PanelIdentify web-based control panelsInfoSource
Essential Blocks < 4.4.3 - Local File InclusionCVE-2023-6623Identify critical remote vulnerabilitiesCriticalSource
EuroTel ETL3100 - Default LoginIdentify default logins in web-based control panelsHighSource
EventON (Free < 2.2.8, Premium < 4.5.5) - Information DisclosureCVE-2024-0235Identify critical remote vulnerabilitiesMediumSource
EventON <= 2.1 - Missing AuthorizationCVE-2023-2796Identify critical remote vulnerabilitiesMediumSource
EventON Lite < 2.1.2 - Arbitrary File DownloadCVE-2023-3219Identify critical remote vulnerabilitiesMediumSource
Eventum Login Panel - DetectIdentify web-based control panelsInfoSource
Evertz SDVN 3080ipx-10G - Unauthenticated Arbitrary Command InjectionCVE-2025-4009Identify critical remote vulnerabilitiesCriticalSource
ExaGrid Manager Login Panel - DetectIdentify web-based control panelsInfoSource
Exchange Server - Remote Code ExecutionCVE-2021-34473Identify critical remote vulnerabilitiesCriticalSource
Exolis Engage Panel - DetectIdentify web-based control panelsInfoSource
Extensive VC Addons for WPBakery page builder < 1.9.1 - Unauthenticated RCECVE-2023-0159Identify critical remote vulnerabilitiesHighSource
Extreme NetConfig UI Panel - DetectIdentify web-based control panelsInfoSource
EyesOfNetwork - Hardcoded API KeyCVE-2020-8657Identify critical remote vulnerabilitiesCriticalSource
EyesOfNetwork - Hardcoded API Key & SQL InjectionCVE-2020-8656Identify critical remote vulnerabilitiesCriticalSource
EyouCms v1.6.3 - Information DisclosureCVE-2023-37645Identify critical remote vulnerabilitiesMediumSource
F-Secure Policy Manager Server Login Panel - DetectIdentify web-based control panelsInfoSource
F-logic DataCube3 - SQL InjectionCVE-2024-31750Identify critical remote vulnerabilitiesCriticalSource
F5 Admin Interface - DetectIdentify web-based control panelsInfoSource
F5 BIG-IP TMUI - Remote Code ExecutionCVE-2020-5902Identify critical remote vulnerabilitiesCriticalSource
F5 BIG-IP iControl - REST Auth Bypass RCECVE-2022-1388Identify critical remote vulnerabilitiesCriticalSource
F5 BIG-IP iControl REST Panel - DetectIdentify web-based control panelsInfoSource
F5 iControl REST - Remote Command ExecutionCVE-2021-22986Identify critical remote vulnerabilitiesCriticalSource
FASTPANEL Login Panel - DetectIdentify web-based control panelsInfoSource
FOG Project < 1.5.10.34 - Remote Command ExecutionCVE-2024-39914Identify critical remote vulnerabilitiesCriticalSource
FOSSBilling Panel - DetectIdentify web-based control panelsInfoSource
FREEDOM Administration - Default LoginIdentify critical remote vulnerabilitiesCriticalSource
FUEL CMS 1.4.1 - Remote Code ExecutionCVE-2018-16763Identify critical remote vulnerabilitiesCriticalSource
Falcosidekick UI Login Panel - DetectIdentify web-based control panelsInfoSource
Faraday Login Panel - DetectIdentify web-based control panelsInfoSource
FastAdmin < V1.3.4.20220530 - Path TraversalCVE-2024-7928Identify critical remote vulnerabilitiesMediumSource
FastCGI Test PageIdentify web-based control panelsInfoSource
Fastify Swagger-UI - Information DisclosureCVE-2024-22207Identify critical remote vulnerabilitiesMediumSource
Feiyuxing Enterprise-Level Management System - Default LoginIdentify default logins in web-based control panelsHighSource
Femtocell Access Point Panel - DetectIdentify web-based control panelsInfoSource
Fides Privacy Center ≤ 2.39.1 - Server-Side URL DisclosureCVE-2024-31223Identify critical remote vulnerabilitiesMediumSource
File Browser Login Panel - DetectIdentify web-based control panelsInfoSource
FileCatalyst File Transfer Solution - DetectIdentify web-based control panelsInfoSource
FileGator Panel - DetectIdentify web-based control panelsInfoSource
FileMage Gateway - Directory TraversalCVE-2023-39026Identify critical remote vulnerabilitiesHighSource
Filegator - Default LoginIdentify default logins in web-based control panelsHighSource
Financial Transaction Manager Login Panel - DetectIdentify web-based control panelsInfoSource
Fireware XTM Login Panel - DetectIdentify web-based control panelsInfoSource
Flahscookie Superadmin Login Panel - DetectIdentify web-based control panelsInfoSource
Flatpress < 1.3 - Path TraversalCVE-2023-0947Identify critical remote vulnerabilitiesCriticalSource
FleetCart 4.1.1 - Information DisclosureCVE-2024-5230Identify critical remote vulnerabilitiesMediumSource
Flexible Checkout Fields for WooCommerce <= 2.3.1 - Unauthenticated Arbitrary Plugin Settings UpdateCVE-2020-36731Identify critical remote vulnerabilitiesHighSource
FlightPath Login Panel - DetectIdentify web-based control panelsInfoSource
Flock Safety Camera Admin Panel - Detecthttp-iotInfoSource
Flowise 1.6.5 - Authentication BypassIdentify critical remote vulnerabilitiesHighSource
Flowise <= 1.8.2 Authentication BypassCVE-2024-8181Identify critical remote vulnerabilitiesCriticalSource
FlureeDB Admin Console Login Panel - DetectIdentify web-based control panelsInfoSource
FootPrints Service Core Login Panel - DetectIdentify web-based control panelsInfoSource
Forcepoint ApplianceIdentify web-based control panelsInfoSource
ForgeRock OpenAM <7.0 - Remote Code ExecutionCVE-2021-35464Identify critical remote vulnerabilitiesCriticalSource
Fork CMS - InstallerIdentify critical remote vulnerabilitiesCriticalSource
Form-Maker < 1.15.20 - Unauthenticated Arbitrary File UploadCVE-2023-4666Identify critical remote vulnerabilitiesCriticalSource
Formidable Forms < 2.05.02 - Cross-Site ScriptingCVE-2017-20192Identify critical remote vulnerabilitiesMediumSource
FortiADC Login Panel - DetectIdentify web-based control panelsInfoSource
FortiAP Login Panel - DetectIdentify web-based control panelsInfoSource
FortiAuthenticator - DetectIdentify web-based control panelsInfoSource
FortiClient Endpoint Management Server Panel - DetectIdentify web-based control panelsInfoSource
FortiOS Admin Login Panel - DetectIdentify web-based control panelsInfoSource
FortiRecorder Panel - DetectIdentify web-based control panelsInfoSource
FortiWLM - Directory TraversalCVE-2023-34990Identify critical remote vulnerabilitiesCriticalSource
Fortinet FortiDDoS PanelIdentify web-based control panelsInfoSource
Fortinet FortiMail Login Panel - DetectIdentify web-based control panelsInfoSource
Fortinet FortiNAC Login Panel - DetectIdentify web-based control panelsInfoSource
Fortinet FortiOS - Credentials DisclosureCVE-2018-13379Identify critical remote vulnerabilitiesCriticalSource
Fortinet FortiOS Management Interface Panel - DetectIdentify web-based control panelsInfoSource
Fortinet FortiTester Login Panel - DetectIdentify web-based control panelsInfoSource
Fortinet FortiWLM Login Panel - DetectIdentify web-based control panelsInfoSource
Fortinet FortiWeb - SQL InjectionCVE-2025-25257Identify critical remote vulnerabilitiesCriticalSource
Fortinet FortiWeb Login Panel - DetectIdentify web-based control panelsInfoSource
Fortinet Forticlient Endpoint Management Server - SQL InjectionCVE-2023-48788Identify critical remote vulnerabilitiesCriticalSource
Fortinet Login Panel - DetectIdentify web-based control panelsInfoSource
Fortra GoAnywhere MFT - Authentication BypassCVE-2024-0204Identify critical remote vulnerabilitiesCriticalSource
FoxCMS v.1.2.5 - Remote Code ExecutionCVE-2025-29306Identify critical remote vulnerabilitiesCriticalSource
Frappe Helpdesk Login Panel - DetectIdentify web-based control panelsInfoSource
Frappe Panel - DetectIdentify web-based control panelsInfoSource
Free5gc 3.2.1 - Information DisclosureCVE-2022-38870Identify critical remote vulnerabilitiesHighSource
FreeIPA Identity Management Login Panel - DetectIdentify web-based control panelsInfoSource
FreePBX - CVE-2025-57819 BackdoorIdentify critical remote vulnerabilitiesHighSource
FreePBX Admin Panel - DetectIdentify web-based control panelsInfoSource
Freshrss Panel - DetectIdentify web-based control panelsInfoSource
Friendica Panel - DetectIdentify web-based control panelsInfoSource
Froxlor Server Management Login Panel - DetectIdentify web-based control panelsInfoSource
Fuel CMS 1.4.7 - SQL InjectionCVE-2020-17463Identify critical remote vulnerabilitiesCriticalSource
Fuel CMS Login Panel - DetectIdentify web-based control panelsInfoSource
Fuji Xerox Printer Panel - DetectIdentify web-based control panelsInfoSource
Fujian Kelixin Communication - Command InjectionCVE-2024-2621Identify critical remote vulnerabilitiesMediumSource
Fumasoft Cloud - SQL InjectionIdentify critical remote vulnerabilitiesCriticalSource
Fumeng - SQL InjectionIdentify critical remote vulnerabilitiesCriticalSource
FusionAuth Admin Panel - DetectIdentify web-based control panelsInfoSource
GL.iNET SSID Key DisclosureCVE-2023-31478Identify critical remote vulnerabilitiesHighSource
GLPI 9.2/<9.5.6 - Information DisclosureCVE-2021-39211Identify critical remote vulnerabilitiesMediumSource
GLPI < 10.0.17 - Pre-Auth SQL InjectionCVE-2025-24799Identify critical remote vulnerabilitiesHighSource
GLPI <=10.0.2 - Remote Command ExecutionCVE-2022-35914Identify critical remote vulnerabilitiesCriticalSource
GLPI Panel - DetectIdentify web-based control panelsInfoSource
GNU Mailman Panel - DetectIdentify web-based control panelsInfoSource
GXD5 Pacs Connexion Login Panel - DetectIdentify web-based control panelsInfoSource
GYRA Master Admin Login Panel - DetectIdentify web-based control panelsInfoSource
Gargoyle Router Management Utility Admin Login Panel - DetectIdentify web-based control panelsInfoSource
GenieACS => 1.2.8 - OS Command InjectionCVE-2021-46704Identify critical remote vulnerabilitiesCriticalSource
GeoServer - Missing Authorization on REST API IndexCVE-2025-27505Identify critical remote vulnerabilitiesMediumSource
GeoServer - XML External Entity InjectionCVE-2025-58360Identify critical remote vulnerabilitiesHighSource
GeoServer <1.2.2 - Remote Code ExecutionCVE-2022-24816Identify critical remote vulnerabilitiesCriticalSource
GeoServer Login Panel - DetectIdentify web-based control panelsInfoSource
Geoserver Admin - Default LoginIdentify default logins in web-based control panelsHighSource
Gibbon v25.0.0 - Local File InclusionCVE-2023-34598Identify critical remote vulnerabilitiesCriticalSource
Gira HomeServer 4 Login Panel - DetectIdentify web-based control panelsInfoSource
GitHub Enterprise - Encrypted SAMLIdentify web-based control panelsInfoSource
GitLab CE/EE - Remote Code ExecutionCVE-2021-22205Identify critical remote vulnerabilitiesCriticalSource
GitLab GraphQL API User EnumerationCVE-2021-4191Identify critical remote vulnerabilitiesMediumSource
GitLab Instance Explore - DetectIdentify web-based control panelsInfoSource
Gitblit - Default LoginIdentify default logins in web-based control panelsHighSource
Gitblit Login Panel - DetectIdentify web-based control panelsInfoSource
Gitea 1.4.0 - Remote Code ExecutionIdentify critical remote vulnerabilitiesCriticalSource
Gitea Login Panel - DetectIdentify web-based control panelsInfoSource
Github Enterprise Login Panel - DetectIdentify web-based control panelsInfoSource
Gitlab CE/EE 13.4 - 13.6.2 - Information DisclosureCVE-2020-26413Identify critical remote vulnerabilitiesMediumSource
Gitlab Default LoginIdentify default logins in web-based control panelsHighSource
Gitlab Login Panel - DetectIdentify web-based control panelsInfoSource
Gitlab SAML - DetectionIdentify web-based control panelsInfoSource
Gladinet CentreStack & TrioFox - Local File InclusionCVE-2025-11371Identify critical remote vulnerabilitiesMediumSource
Gladinet CentreStack & Triofox - Hardcoded CredentialsCVE-2025-14611Identify critical remote vulnerabilitiesCriticalSource
Gladinet CentreStack < 16.4.10315.56368 Use of Hard-coded Key Leads to Unauthenticated RCECVE-2025-30406Identify critical remote vulnerabilitiesCriticalSource
Glimpse Diagnostics - Sensitive Data ExposureIdentify critical remote vulnerabilitiesHighSource
Glowroot - PanelIdentify web-based control panelsInfoSource
GnuBoard5 5.5.16 - Open RedirectCVE-2024-37656Identify critical remote vulnerabilitiesMediumSource
Go.Control Event Administration Panel - DetectIdentify web-based control panelsInfoSource
GoAnywhere - Authentication BypassCVE-2025-10035Identify critical remote vulnerabilitiesCriticalSource
GoAnywhere Managed File Transfer Login Panel - DetectIdentify web-based control panelsInfoSource
GoCD Login Panel - DetectIdentify web-based control panelsInfoSource
Gogs (Go Git Service) - SQL InjectionCVE-2014-8682Identify critical remote vulnerabilitiesHighSource
Gogs (Go Git Service) 0.11.66 - Remote Code ExecutionCVE-2018-18925Identify critical remote vulnerabilitiesCriticalSource
Gogs Login Panel - DetectIdentify web-based control panelsInfoSource
Google Earth Enterprise - Default LoginIdentify default logins in web-based control panelsHighSource
Gophish Login Panel - DetectIdentify web-based control panelsInfoSource
Gotify Login Panel - DetectIdentify web-based control panelsInfoSource
Gradio - Local File InclusionIdentify critical remote vulnerabilitiesCriticalSource
Gradle Develocity Build Cache Node Login Panel - DetectIdentify web-based control panelsInfoSource
Gradle Enterprise Build Cache Node Login Panel - DetectIdentify web-based control panelsInfoSource
Grafana & Zabbix Integration - Credentials DisclosureCVE-2022-26148Identify critical remote vulnerabilitiesCriticalSource
Grafana - Default LoginIdentify default logins in web-based control panelsHighSource
Grafana - Exposes DingDing API KeysIdentify critical remote vulnerabilitiesMediumSource
Grafana Login Panel - DetectIdentify web-based control panelsInfoSource
Grafana Snapshot - Authentication BypassCVE-2021-39226Identify critical remote vulnerabilitiesHighSource
Grafana v8.x - Arbitrary File ReadCVE-2021-43798Identify critical remote vulnerabilitiesHighSource
Grandstream Networks UCM6200 Series SQL Injection VulnerabilityCVE-2020-5722Identify critical remote vulnerabilitiesCriticalSource
Graphite Browser Login Panel - DetectIdentify web-based control panelsInfoSource
Graylog Login Panel - DetectIdentify web-based control panelsInfoSource
Greenbone Security Assistant Panel - DetectIdentify web-based control panelsInfoSource
Group-IB Managed XDR Login Panel - DetectIdentify web-based control panelsInfoSource
Gryphon Panel - DetectIdentify web-based control panelsInfoSource
Gurock TestRail Application files.md5 ExposureCVE-2021-40875Identify critical remote vulnerabilitiesHighSource
H2 Console Web Login Panel - DetectIdentify web-based control panelsInfoSource
H2O ImportFiles - Local File InclusionCVE-2023-6038Identify critical remote vulnerabilitiesHighSource
H3C ER8300G2-X - Password DisclosureCVE-2024-32238Identify critical remote vulnerabilitiesCriticalSource
H3c IMC - Remote Code ExecutionIdentify critical remote vulnerabilitiesCriticalSource
HAL Management Console PanelIdentify web-based control panelsInfoSource
HCL BigFix Login Panel - DetectIdentify web-based control panelsInfoSource
HOOBS Panel - DetectIdentify web-based control panelsInfoSource
HP 1820-8G Switch J9979A - Default LoginIdentify default logins in web-based control panelsHighSource
HP Service Manager Login Panel - DetectIdentify web-based control panelsInfoSource
HP Virtual Connect Manager Login Panel - DetectIdentify web-based control panelsInfoSource
HPE OfficeConnect Switch - Panel DetectIdentify web-based control panelsInfoSource
HPE OneView - Panel DetectIdentify web-based control panelsInfoSource
HTTP File Server <2.3c - Remote Command ExecutionCVE-2014-6287Identify critical remote vulnerabilitiesCriticalSource
HTTPBin Login Panel - DetectIdentify web-based control panelsInfoSource
HYPERPLANNING Login Panel - DetectIdentify web-based control panelsInfoSource
Haivision Gateway Login Panel - DetectIdentify web-based control panelsInfoSource
Haivision Media Platform Login Panel - DetectIdentify web-based control panelsInfoSource
Hangfire Dashboard Panel - DetectIdentify web-based control panelsInfoSource
Harbor Login Panel - DetectIdentify web-based control panelsInfoSource
HashiCorp Consul Web UI Login Panel - DetectIdentify web-based control panelsInfoSource
Hashicorp Consul Agent - DetectIdentify web-based control panelsInfoSource
Hestia Control Panel Login - DetectIdentify web-based control panelsInfoSource
Hide My WP Ghost < 5.2.02 - Hidden Login Page DisclosureCVE-2024-6420Identify critical remote vulnerabilitiesHighSource
HighMail Admin Login Panel - DetectIdentify web-based control panelsInfoSource
Hikvision IP ping.php - Command ExecutionCVE-2023-6895Identify critical remote vulnerabilitiesMediumSource
Hitachi Pentaho Business Analytics Server - Bypass AuthorizationCVE-2022-43939Identify critical remote vulnerabilitiesHighSource
HiveManager Login Panel - DetectIdentify web-based control panelsInfoSource
Home Assistant PanelIdentify web-based control panelsInfoSource
Home Assistant Supervisor - Authentication BypassCVE-2023-27482Identify critical remote vulnerabilitiesCriticalSource
Homebridge Panel - DetectIdentify web-based control panelsInfoSource
Homematic Panel - DetectIdentify web-based control panelsInfoSource
Homer Panel - DetectIdentify web-based control panelsInfoSource
Honeywell Excel Web Control Login Panel - DetectIdentify web-based control panelsInfoSource
Honeywell PM43 Printers - Command InjectionCVE-2023-3710Identify critical remote vulnerabilitiesCriticalSource
Hongjing e-HR 2020 - SQL InjectionCVE-2023-6655Identify critical remote vulnerabilitiesHighSource
Hookbot Rat Panel - DetectIdentify web-based control panelsInfoSource
Horde Login Panel - DetectIdentify web-based control panelsInfoSource
Horde Webmail Login Panel - DetectIdentify web-based control panelsInfoSource
Hospital Management System 1.0 - SQL InjectionCVE-2022-34590Identify critical remote vulnerabilitiesHighSource
Hospital Management System 1.0 - SQL InjectionCVE-2022-32094Identify critical remote vulnerabilitiesCriticalSource
Hospital Management System 1.0 - SQL InjectionCVE-2022-38637Identify critical remote vulnerabilitiesCriticalSource
Hospital Management System Login Panel - DetectIdentify web-based control panelsInfoSource
Hotel Booking Lite < 4.8.5 - Arbitrary File Download & DeletionCVE-2023-5991Identify critical remote vulnerabilitiesCriticalSource
Hoteldruid v3.0.5 - SQL InjectionCVE-2023-43374Identify critical remote vulnerabilitiesCriticalSource
HuangDou UTCMS V9 - OS Command InjectionCVE-2024-9916Identify critical remote vulnerabilitiesHighSource
Huawei HG532e - Default CredentialIdentify default logins in web-based control panelsHighSource
Huawei HG532e Router Panel - DetectIdentify web-based control panelsInfoSource
Huawei HoloSens SDC - PanelIdentify web-based control panelsInfoSource
Huginn Login Panel - DetectIdentify web-based control panelsInfoSource
Huly Login Panel - DetectIdentify web-based control panelsInfoSource
Hybris - Default LoginIdentify default logins in web-based control panelsHighSource
Hybris Administration Console Login Panel - DetectIdentify web-based control panelsInfoSource
Hybris Management Console Login Panel - DetectIdentify web-based control panelsInfoSource
Hydra Router Dashboard - DetectIdentify web-based control panelsInfoSource
HyperDX Panel - DetectIdentify web-based control panelsInfoSource
HyperTest Common Dashboard - DetectIdentify web-based control panelsInfoSource
Hytec Inter HWL-2511-SS - Remote Command ExecutionCVE-2022-36553Identify critical remote vulnerabilitiesCriticalSource
IBM Advanced System Management Panel - DetectIdentify web-based control panelsInfoSource
IBM BigFix Platform - Information DisclosureCVE-2019-4061Identify critical remote vulnerabilitiesMediumSource
IBM Data Risk Manager - Authentication Bypass via SAMLCVE-2020-4427Identify critical remote vulnerabilitiesCriticalSource
IBM Decision Center Business Console - Default LoginIdentify default logins in web-based control panelsHighSource
IBM Decision Center Enterprise Console - Default LoginIdentify default logins in web-based control panelsHighSource
IBM Decision Center Enterprise Console - Panel DetectionIdentify web-based control panelsInfoSource
IBM Decision Server Console - Default LoginIdentify default logins in web-based control panelsHighSource
IBM Decision Server Console Panel - DetectIdentify web-based control panelsInfoSource
IBM Maximo Login Panel - DetectIdentify web-based control panelsInfoSource
IBM OpenAdmin Tool - PanelIdentify web-based control panelsInfoSource
IBM Operational Decision Manager Panel - DetectIdentify web-based control panelsInfoSource
IBM Planning Analytics - Authentication Bypass & Remote Code Execution Version DetectionCVE-2019-4716Identify critical remote vulnerabilitiesCriticalSource
IBM Power HMC - Default LoginIdentify default logins in web-based control panelsHighSource
IBM Security Access Manager Login Panel - DetectIdentify web-based control panelsInfoSource
IBM Security Verify Access Login - PanelIdentify web-based control panelsInfoSource
IBM Service Assistant Login Panel - DetectIdentify web-based control panelsInfoSource
IBM WebSphere Application Server Community Edition Admin Login Panel - DetectIdentify web-based control panelsInfoSource
IBM WebSphere Portal Login Panel - DetectIdentify web-based control panelsInfoSource
IBM iNotes Login Panel - DetectIdentify web-based control panelsInfoSource
ICC PRO Login Panel - DetectIdentify web-based control panelsInfoSource
ICE HRM Login - DetectIdentify web-based control panelsInfoSource
ICT Protege WX Login Panel - DetectIdentify web-based control panelsInfoSource
ICTBroadcast Login Panel - DetectIdentify web-based control panelsInfoSource
IDEMIA BIOMetrics - Default LoginIdentify default logins in web-based control panelsMediumSource
ILIAS Login Panel - DetectIdentify web-based control panelsInfoSource
INTELBRAS TELEFONE IP TIP200 60.61.75.22 - Local File InclusionCVE-2020-24285Identify critical remote vulnerabilitiesHighSource
IPS Community Suite - Unauthenticated SQL InjectionCVE-2024-30163Identify critical remote vulnerabilitiesCriticalSource
IPdiva Mediation Login Panel - DetectIdentify web-based control panelsInfoSource
IPeakCMS 3.5 - SQL InjectionCVE-2021-3018Identify critical remote vulnerabilitiesCriticalSource
IRISNext Login Panel - DetectIdentify web-based control panelsInfoSource
ISPConfig Admin Panel - Default LoginIdentify default logins in web-based control panelsHighSource
ISPConfig Hosting Control Panel - Default LoginIdentify default logins in web-based control panelsHighSource
IceWarp Email Client - Cross Site ScriptingCVE-2023-39598Identify critical remote vulnerabilitiesMediumSource
IceWarp Login Panel - DetectIdentify web-based control panelsInfoSource
IceWarp WebClient - Remote Code ExecutionIdentify critical remote vulnerabilitiesCriticalSource
IceWarp Webmail Server v10.2.1 - Cross Site ScriptingCVE-2023-37728Identify critical remote vulnerabilitiesMediumSource
Icinga Exposed DashboardIdentify critical remote vulnerabilitiesMediumSource
Icinga Web 2 Login Panel - DetectIdentify web-based control panelsInfoSource
IdeaCMS <= 1.7 - SQL InjectionCVE-2025-5569Identify critical remote vulnerabilitiesMediumSource
Ilch CMS Admin Login Panel - DetectIdentify web-based control panelsInfoSource
ImageResizer Debug - Information ExposureIdentify critical remote vulnerabilitiesLowSource
Immich Panel - DetectIdentify web-based control panelsInfoSource
ImpressCMS < 1.4.3 - SQL InjectionCVE-2021-26599Identify critical remote vulnerabilitiesCriticalSource
ImpressCMS <1.4.3 - Incorrect AuthorizationCVE-2021-26598Identify critical remote vulnerabilitiesMediumSource
InduSoft Web Studio NTWebServer Directory Traversal VulnerabilityCVE-2014-0780Identify critical remote vulnerabilitiesCriticalSource
InfluxDB <1.7.6 - Authentication BypassCVE-2019-20933Identify critical remote vulnerabilitiesCriticalSource
InfluxDB Admin Interface Panel - DetectIdentify web-based control panelsInfoSource
Infoblox NIOS Login Panel - DetectIdentify web-based control panelsInfoSource
Inspur Clusterengine 4 - Default Admin LoginIdentify default logins in web-based control panelsHighSource
Inspur Clusterengine V4 SYSshell - Remote Command ExecutionCVE-2020-21224Identify critical remote vulnerabilitiesCriticalSource
InstaWP Connect < 0.1.0.86 - Local PHP File InclusionCVE-2025-2636Identify critical remote vulnerabilitiesCriticalSource
Integrate Google Drive <= 1.5.3 - Information DisclosureCVE-2025-12139Identify critical remote vulnerabilitiesHighSource
Integrated Management Module - Default LoginIdentify default logins in web-based control panelsHighSource
Intel Active Management - Authentication BypassCVE-2017-5689Identify critical remote vulnerabilitiesCriticalSource
Intelbras NPLUG 1.0.0.14 - Authentication BypassCVE-2018-12455Identify critical remote vulnerabilitiesHighSource
Intelbras Router Login Panel - DetectIdentify web-based control panelsInfoSource
Intelbras Router Panel - DetectIdentify web-based control panelsInfoSource
Intelbras Switch - Information DisclosureCVE-2023-36144Identify critical remote vulnerabilitiesHighSource
Intelbras WRN 150 - Authentication BypassCVE-2017-14942Identify critical remote vulnerabilitiesCriticalSource
Intellian Aptus Web Login Panel - DetectIdentify web-based control panelsInfoSource
Internet Multi Server Control Panel - DetectIdentify web-based control panelsInfoSource
Invision Community <=5.0.6 Unauthenticated RCE via Template InjectionCVE-2025-47916Identify critical remote vulnerabilitiesCriticalSource
Issabel Login Panel - DetectIdentify web-based control panelsInfoSource
Issabel PBX 4.0.0-6 - Directory ListingCVE-2023-37599Identify critical remote vulnerabilitiesHighSource
Ivanti Cloud Services Appliance - Path TraversalCVE-2024-8963Identify critical remote vulnerabilitiesCriticalSource
Ivanti Connect Secure - Stack-based Buffer OverflowCVE-2025-0282Identify critical remote vulnerabilitiesCriticalSource
Ivanti Connect Secure Panel - DetectIdentify web-based control panelsInfoSource
Ivanti EPM Cloud Services Appliance Code InjectionCVE-2021-44529Identify critical remote vulnerabilitiesCriticalSource
Ivanti Endpoint Manager Mobile (EPMM) - Authentication BypassCVE-2023-35078Identify critical remote vulnerabilitiesCriticalSource
Ivanti ICS - Authentication BypassCVE-2023-46805Identify critical remote vulnerabilitiesHighSource
Ivanti Incapptic Connect Panel - DetectIdentify web-based control panelsInfoSource
Ivanti Traffic Manager Panel - DetectIdentify web-based control panelsInfoSource
Ivanti(R) Cloud Services Appliance - PanelIdentify web-based control panelsInfoSource
JBoss SOA Platform Login Panel - DetectIdentify web-based control panelsInfoSource
JBoss WS JUDDI Console Panel - DetectIdentify web-based control panelsInfoSource
JBoss jBPM Administration Console - Default LoginIdentify default logins in web-based control panelsHighSource
JBoss jBPM Administration Console Login Panel - DetectIdentify web-based control panelsInfoSource
JEHC-BPM - Remote Code ExecuteCVE-2025-45854Identify critical remote vulnerabilitiesCriticalSource
JFinalCMS v5.0.0 - Directory TraversalCVE-2023-41599Identify critical remote vulnerabilitiesMediumSource
JFrog Artifactory Artifacts ExposureIdentify critical remote vulnerabilitiesLowSource
JFrog Artifactory Build - ExposureIdentify critical remote vulnerabilitiesMediumSource
JFrog Login Panel - DetectIdentify web-based control panelsInfoSource
Jalios JCMS Login Panel - DetectIdentify web-based control panelsInfoSource
Jamf MDM Login Panel - DetectIdentify web-based control panelsInfoSource
Jamf Pro Login Panel - DetectIdentify web-based control panelsInfoSource
Jamf Pro Setup Assistant Panel - DetectIdentify web-based control panelsInfoSource
Jan v0.4.12 'readFileSync' - Path TraversalCVE-2024-36857Identify critical remote vulnerabilitiesHighSource
Jedox Web Login Panel - DetectIdentify web-based control panelsInfoSource
JeePlus CMS - SQL InjectionIdentify critical remote vulnerabilitiesHighSource
Jeecg Boot <= 2.4.5 - Information DisclosureCVE-2021-37304Identify critical remote vulnerabilitiesHighSource
Jeecg Boot <= 2.4.5 - Sensitive Information DisclosureCVE-2021-37305Identify critical remote vulnerabilitiesHighSource
Jeecg P3 Biz Chat - Local File InclusionCVE-2023-33510Identify critical remote vulnerabilitiesHighSource
Jeecg-Boot v3.5.1 - SQL InjectionCVE-2023-38992Identify critical remote vulnerabilitiesCriticalSource
Jeecg-boot 3.5.0 qurestSql - SQL InjectionCVE-2023-1454Identify critical remote vulnerabilitiesMediumSource
JeecgBoot 3.5.0 - SQL InjectionCVE-2023-34659Identify critical remote vulnerabilitiesCriticalSource
JeecgBoot v3.7.1 - SQL InjectionCVE-2024-48307Identify critical remote vulnerabilitiesCriticalSource
Jeedom - Default LoginIdentify default logins in web-based control panelsHighSource
Jeedom Login Panel - DetectIdentify web-based control panelsInfoSource
Jellyfin Console - Default LoginIdentify default logins in web-based control panelsHighSource
Jellyseerr Login Panel - DetectIdentify web-based control panelsInfoSource
Jenkins - Remote Command InjectionCVE-2018-1000861Identify critical remote vulnerabilitiesCriticalSource
Jenkins API Panel - DetectIdentify web-based control panelsInfoSource
Jenkins Command Line Interface (CLI) Path Traversal VulnerabilityCVE-2024-23897Identify critical remote vulnerabilitiesCriticalSource
Jenkins Default LoginIdentify default logins in web-based control panelsHighSource
Jenkins Login DetectedIdentify web-based control panelsInfoSource
Jenkins Users - ExposureIdentify critical remote vulnerabilitiesInfoSource
JetBrains TeamCity > 2023.11.3 - Authentication BypassCVE-2024-23917Identify critical remote vulnerabilitiesCriticalSource
Jinhe OA - SQL InjectionIdentify critical remote vulnerabilitiesHighSource
Joget Panel - DetectIdentify web-based control panelsInfoSource
Joomla HTTP Header Unauthenticated - Remote Code ExecutionCVE-2015-8562Identify critical remote vulnerabilitiesHighSource
Joomla! <3.7.1 - SQL InjectionCVE-2017-8917Identify critical remote vulnerabilitiesCriticalSource
Joomla! Core SQL InjectionCVE-2015-7297Identify critical remote vulnerabilitiesHighSource
Joomla! PanelIdentify web-based control panelsInfoSource
Joomla! Webservice - Password DisclosureCVE-2023-23752Identify critical remote vulnerabilitiesMediumSource
JoomlaUX JUX Real Estate 3.4.0 - Reflected XSSCVE-2025-2127Identify critical remote vulnerabilitiesMediumSource
Joplin Server Login - PanelIdentify web-based control panelsInfoSource
Jorani 1.0.0 - Remote Code ExecutionCVE-2023-26469Identify critical remote vulnerabilitiesCriticalSource
Jorani Login Panel - DetectIdentify web-based control panelsInfoSource
Journyx - XML External Entities Injection (XXE)CVE-2024-6893Identify critical remote vulnerabilitiesHighSource
Journyx 11.5.4 - Reflected Cross Site ScriptingCVE-2024-6892Identify critical remote vulnerabilitiesMediumSource
JshERP Boot Panel - DetectIdentify web-based control panelsInfoSource
JumpServer > 3.6.4 - Information DisclosureCVE-2023-42442Identify critical remote vulnerabilitiesHighSource
JumpServer Login Panel - DetectIdentify web-based control panelsInfoSource
Juniper J-Web - Remote Code ExecutionCVE-2023-36845Identify critical remote vulnerabilitiesCriticalSource
Juniper J-Web Panel - DetectIdentify web-based control panelsInfoSource
Jupyter Notebook - Remote Command ExecutionIdentify critical remote vulnerabilitiesHighSource
Jupyter Notebook Login Panel - DetectIdentify web-based control panelsInfoSource
Jupyterhub - Default LoginIdentify default logins in web-based control panelsHighSource
JustBoil.me Images Plugin - Exposed Image UploadIdentify critical remote vulnerabilitiesMediumSource
KLog Server - Default LoginIdentify default logins in web-based control panelsHighSource
Kanboard - Default LoginIdentify default logins in web-based control panelsHighSource
Kanboard Login Panel - DetectIdentify web-based control panelsInfoSource
Kaseya VSA < 9.5.7 - Credential Disclosure via Windows AgentCVE-2021-30116Identify critical remote vulnerabilitiesCriticalSource
Kasm Login Panel - DetectIdentify web-based control panelsInfoSource
Kavita Login Panel - DetectIdentify web-based control panelsInfoSource
Kentico - Installer Privilege EscalationCVE-2017-17736Identify critical remote vulnerabilitiesCriticalSource
Kerio Connect Login Panel - DetectIdentify web-based control panelsInfoSource
Kerio Controle Panel - DetectIdentify web-based control panelsInfoSource
Kettle - Default LoginIdentify default logins in web-based control panelsMediumSource
Kettle Panel - DetectIdentify web-based control panelsInfoSource
KeyCloak - Information ExposureCVE-2020-27838Identify critical remote vulnerabilitiesMediumSource
Keycloak Admin Console Configuration DisclosureIdentify critical remote vulnerabilitiesLowSource
Keycloak Admin Login Panel - DetectIdentify web-based control panelsInfoSource
Kiali - DetectIdentify web-based control panelsInfoSource
Kibana Login Panel - DetectIdentify web-based control panelsInfoSource
Kibana Timelion - Arbitrary Code ExecutionCVE-2019-7609Identify critical remote vulnerabilitiesCriticalSource
Kiteworks PCN Panel - DetectIdentify web-based control panelsInfoSource
KiviCare Clinic & Patient Management System (EHR) <= 3.6.4 - SQL InjectionCVE-2024-11728Identify critical remote vulnerabilitiesHighSource
Kiwi TCMS Information DisclosureIdentify critical remote vulnerabilitiesHighSource
Kiwi TCMS Login Panel - DetectIdentify web-based control panelsInfoSource
Koel Panel - DetectIdentify web-based control panelsInfoSource
Kong Manager OSS/Admin - ExposureIdentify web-based control panelsMediumSource
Kopano WebApp Login Panel - DetectIdentify web-based control panelsInfoSource
Kraken Cluster Monitoring Dashboard - DetectIdentify web-based control panelsInfoSource
Krpano Panorama Viewer - DetectionIdentify web-based control panelsInfoSource
KubeOperator Foreground `kubeconfig` - File DownloadCVE-2023-22480Identify critical remote vulnerabilitiesHighSource
KubePi <= v1.6.4 LoginLogsSearch - Unauthorized AccessCVE-2023-22478Identify critical remote vulnerabilitiesHighSource
KubeView <=0.1.31 - Information DisclosureCVE-2022-45933Identify critical remote vulnerabilitiesCriticalSource
KubeView Dashboard - DetectIdentify web-based control panelsInfoSource
Kubernetes API Server - YAML Parsing DoS (Billion Laughs)CVE-2019-11253Identify critical remote vulnerabilitiesHighSource
Kubernetes Enterprise Manager Panel - DetectIdentify web-based control panelsInfoSource
Kubernetes Local Cluster Web View Panel- DetectIdentify web-based control panelsMediumSource
Kubio AI Page Builder <= 2.5.1 - Local File InclusionCVE-2025-2294Identify critical remote vulnerabilitiesCriticalSource
Kyocera TASKalfa printer - Path TraversalCVE-2023-34259Identify critical remote vulnerabilitiesMediumSource
LDAP Account Manager Login Panel - DetectIdentify web-based control panelsInfoSource
LaRecipe < 2.8.1 Remote Code Execution via SSTICVE-2025-53833Identify critical remote vulnerabilitiesCriticalSource
LabKey Server Login Panel - DetectIdentify web-based control panelsInfoSource
Label Studio - Login PanelIdentify web-based control panelsInfoSource
Laminas Project laminas-http - Remote Code ExecutionCVE-2021-3007Identify critical remote vulnerabilitiesCriticalSource
Lancom Router Login Panel - DetectIdentify web-based control panelsInfoSource
Langflow AI - Unauthenticated Remote Code ExecutionCVE-2025-3248Identify critical remote vulnerabilitiesCriticalSource
Langflow AI <= 1.6.9 - CORS MisconfigurationCVE-2025-34291Identify critical remote vulnerabilitiesCriticalSource
Lansweeper Login Panel - DetectIdentify web-based control panelsInfoSource
Lansweeper Unauthenticated SQL InjectionCVE-2019-13462Identify critical remote vulnerabilitiesCriticalSource
Laravel Backpack Admin Login Panel - DetectIdentify web-based control panelsInfoSource
LearnDash LMS < 4.10.2 - Sensitive Information ExposureCVE-2024-1210Identify critical remote vulnerabilitiesMediumSource
LearnDash LMS < 4.10.2 - Sensitive Information Exposure via assignmentsCVE-2024-1209Identify critical remote vulnerabilitiesMediumSource
LearnDash LMS < 4.10.3 - Sensitive Information ExposureCVE-2024-1208Identify critical remote vulnerabilitiesMediumSource
LearnPress < 4.2.7.1 - SQL InjectionCVE-2024-8529Identify critical remote vulnerabilitiesCriticalSource
LearnPress < 4.2.7.1 - SQL InjectionCVE-2024-8522Identify critical remote vulnerabilitiesCriticalSource
LearnPress <= 4.2.5.7 - SQL InjectionCVE-2023-6567Identify critical remote vulnerabilitiesCriticalSource
LearnPress Plugin < 4.2.0 - Unauthenticated Time-Based Blind SQLiCVE-2022-45808Identify critical remote vulnerabilitiesCriticalSource
Lenovo Fan Power Controller Login Panel - DetectIdentify web-based control panelsInfoSource
Leostream Default LoginIdentify default logins in web-based control panelsHighSource
Leostream Login Panel - DetectIdentify web-based control panelsInfoSource
Letta Letta 0.7.12 - Remote Code ExecutionCVE-2025-51482Identify critical remote vulnerabilitiesHighSource
LibreChat <= 0.7.9 - HTML Injection via Accept-Language HeaderCVE-2025-8848Identify critical remote vulnerabilitiesMediumSource
LibreChat Login Panel - DetectionIdentify web-based control panelsInfoSource
LibreNMS Login Panel - DetectIdentify web-based control panelsInfoSource
LibrePhotos Panel - DetectIdentify web-based control panelsInfoSource
LibreSpeed Panel - DetectIdentify web-based control panelsInfoSource
Liferay Login Panel - DetectIdentify web-based control panelsInfoSource
Liferay Portal Unauthenticated < 7.2.1 CE GA2 - Remote Code ExecutionCVE-2020-7961Identify critical remote vulnerabilitiesCriticalSource
Lightdash version <= 0.510.3 Arbitrary File ReadCVE-2023-35844Identify critical remote vulnerabilitiesHighSource
Lin CMS Spring Boot - Default JWT TokenCVE-2022-32430Identify critical remote vulnerabilitiesHighSource
LinShare Login Panel - DetectIdentify web-based control panelsInfoSource
Linear eMerge E3-Series - Information DisclosureCVE-2022-31269Identify critical remote vulnerabilitiesHighSource
Linkerd Panel - DetectIdentify web-based control panelsInfoSource
Linksys Smart Wi-Fi Login Panel - DetectIdentify web-based control panelsInfoSource
ListSERV Maestro <= 9.0-8 RCECVE-2010-1870Identify critical remote vulnerabilitiesMediumSource
ListingPro < 2.6.1 - Arbitrary Plugin Installation/Activation/DeactivationCVE-2020-36719Identify critical remote vulnerabilitiesCriticalSource
ListingPro < 2.6.1 - Sensitive Data DisclosureCVE-2020-36723Identify critical remote vulnerabilitiesHighSource
Live Helper Chat Admin Login Panel - DetectIdentify web-based control panelsInfoSource
LiveZilla Login Panel - DetectIdentify web-based control panelsInfoSource
LocalAI - Partial Local File ReadCVE-2024-6095Identify critical remote vulnerabilitiesMediumSource
LockSelf Login Panel - DetectIdentify web-based control panelsInfoSource
Locklizard Web Viewer Login Panel - DetectIdentify web-based control panelsInfoSource
Login as User or Customer < 3.3 - Privilege EscalationCVE-2022-4305Identify critical remote vulnerabilitiesCriticalSource
Logitech Harmony Pro Installer Portal Login Panel - DetectIdentify web-based control panelsInfoSource
Lomnido Panel - DetectIdentify web-based control panelsInfoSource
Looker Login Panel - DetectIdentify web-based control panelsInfoSource
Loxone Intercom Video Panel - DetectIdentify web-based control panelsInfoSource
Loxone WebInterface Panel - DetectIdentify web-based control panelsInfoSource
Loytec PLC - Default LoginIdentify default logins in web-based control panelsHighSource
Lucee - Default LoginIdentify default logins in web-based control panelsHighSource
Lucee - Unset CredentialsIdentify critical remote vulnerabilitiesHighSource
Lucee < 6.0.1.59 - Remote Code ExecutionIdentify critical remote vulnerabilitiesCriticalSource
Lucee Web and Lucee Server Admin Login Panel - DetectIdentify web-based control panelsInfoSource
M-Bus Converter Web Interface - DetectIdentify web-based control panelsInfoSource
M-Files Web Login Panel - DetectIdentify web-based control panelsInfoSource
MAG Dashboard Login Panel - DetectIdentify web-based control panelsInfoSource
MCMS 5.2.4 - SQL InjectionCVE-2022-25125Identify critical remote vulnerabilitiesCriticalSource
MCMS 5.2.5 - SQL InjectionCVE-2022-23898Identify critical remote vulnerabilitiesCriticalSource
MCP Inspector < 0.14.0 UnauthenticatedRemote Code ExecutionIdentify critical remote vulnerabilitiesCriticalSource
MCP Inspector DetectIdentify web-based control panelsInfoSource
MISP Threat Intelligence Sharing Platform Panel - DetectIdentify web-based control panelsInfoSource
MLFlow < 2.8.1 - Sensitive Information DisclosureCVE-2023-43472Identify critical remote vulnerabilitiesHighSource
MLflow Absolute Path TraversalCVE-2023-3765Identify critical remote vulnerabilitiesCriticalSource
MOFI4500-4GXeLTE-V2 Default LoginIdentify default logins in web-based control panelsHighSource
MPDV Mikrolab GmbH HYDRA X, MIP 2 & FEDRA 2 - Path TraversalCVE-2025-12055Identify critical remote vulnerabilitiesHighSource
MPFTVC Admin Login Panel - DetectIdentify web-based control panelsInfoSource
MSNSwitch Firmware MNT.2408 - Authentication BypassCVE-2022-32429Identify critical remote vulnerabilitiesCriticalSource
MSPControl Login Panel - DetectIdentify web-based control panelsInfoSource
MStore API < 3.9.8 - SQL InjectionCVE-2023-3077Identify critical remote vulnerabilitiesCriticalSource
MStore API <= 3.9.1 - Authentication BypassCVE-2023-2734Identify critical remote vulnerabilitiesCriticalSource
MStore API <= 3.9.2 - Authentication BypassCVE-2023-2732Identify critical remote vulnerabilitiesCriticalSource
MStore API <= 4.10.7 - Unauthorized Account Access and Privilege EscalationCVE-2023-3277Identify critical remote vulnerabilitiesCriticalSource
MachForm Admin Panel - DetectIdentify web-based control panelsInfoSource
Maestro LISTSERV - DetectIdentify web-based control panelsInfoSource
Maestro LuCI Login Panel - DetectIdentify web-based control panelsInfoSource
Mage AI - Insecure Default Authentication SetupCVE-2025-2129Identify critical remote vulnerabilitiesMediumSource
Magnolia CMS Default Login - DetectIdentify default logins in web-based control panelsHighSource
Magnolia CMS Login Panel - DetectIdentify web-based control panelsInfoSource
MagnusBilling - Default LoginIdentify default logins in web-based control panelsHighSource
MagnusBilling - Login PanelIdentify web-based control panelsInfoSource
MailEnable Mail Service < v10 - Cross-Site ScriptingCVE-2025-44148Identify critical remote vulnerabilitiesCriticalSource
MailHog Panel - DetectIdentify web-based control panelsInfoSource
MailWatch Login Panel - DetectIdentify web-based control panelsInfoSource
MainWP Dashboard <= 3.1.2 - Stored Cross-Site ScriptingIdentify critical remote vulnerabilitiesHighSource
MajorDoMo thumb.php - OS Command InjectionCVE-2023-50917Identify critical remote vulnerabilitiesCriticalSource
Maltrail Panel - DetectIdentify web-based control panelsInfoSource
Malwared (Build Your Own Botnet) - DetectIdentify web-based control panelsInfoSource
Malwared BYOB - Unauthenticated Remote Code ExecutionIdentify critical remote vulnerabilitiesCriticalSource
ManageEngine Applications Manager - Default LoginIdentify default logins in web-based control panelsHighSource
ManageEngine ServiceDesk 9.3.9328 - Arbitrary File RetrievalCVE-2017-11512Identify critical remote vulnerabilitiesHighSource
MantisBT <=2.30 - Arbitrary Password Reset/Admin AccessCVE-2017-7615Identify critical remote vulnerabilitiesHighSource
MantisBT Default Admin LoginIdentify default logins in web-based control panelsHighSource
MantisBT Login Panel - DetectIdentify web-based control panelsInfoSource
MapSVG < 6.2.20 - Unauthenticated SQLiCVE-2022-0592Identify critical remote vulnerabilitiesCriticalSource
MapTiler Tileserver-php v2.0 - Unauthenticated File ReadCVE-2025-44137Identify critical remote vulnerabilitiesHighSource
MapTiler Tileserver-php v2.0 - Unauthenticated XSSCVE-2025-44136Identify critical remote vulnerabilitiesMediumSource
MasterSAM Star Gate v11 - Local File InclusionIdentify critical remote vulnerabilitiesMediumSource
MasterStudy LMS WordPress Plugin <= 3.2.5 - SQL InjectionCVE-2024-1512Identify critical remote vulnerabilitiesCriticalSource
Masteriyo LMS <= 1.7.3 - Insecure Direct Object ReferenceCVE-2024-33939Identify critical remote vulnerabilitiesMediumSource
Matomo Panel - DetectIdentify web-based control panelsInfoSource
Mattermost Login - PanelIdentify web-based control panelsInfoSource
MeTube Instance DetectedIdentify web-based control panelsInfoSource
Media Library Assistant < 2.82 - Unauthenticated Limited Local File InclusionCVE-2020-11732Identify critical remote vulnerabilitiesHighSource
Meduza Stealer Panel - DetectIdentify web-based control panelsInfoSource
Memos Panel - DetectIdentify web-based control panelsInfoSource
MeshCentral Login Panel - DetectIdentify web-based control panelsInfoSource
Metabase - Local File InclusionCVE-2021-41277Identify critical remote vulnerabilitiesCriticalSource
Metabase < 0.46.6.1 - Remote Code ExecutionCVE-2023-38646Identify critical remote vulnerabilitiesCriticalSource
Metabase Installer - ExposureIdentify critical remote vulnerabilitiesHighSource
Metabase Login Panel - DetectIdentify web-based control panelsInfoSource
Metasploit Panel - DetectIdentify web-based control panelsInfoSource
Metasploit Setup and Configuration Page - DetectIdentify web-based control panelsInfoSource
MeterSphere Login Panel - DetectIdentify web-based control panelsInfoSource
Metersphere - Arbitrary File ReadCVE-2023-25573Identify critical remote vulnerabilitiesHighSource
Micro Focus Application Lifecycle Management - PanelIdentify web-based control panelsInfoSource
Micro Focus Filr Login Panel - DetectIdentify web-based control panelsInfoSource
Micro Focus Vibe Login Panel - DetectIdentify web-based control panelsInfoSource
Microsoft Exchange - Authentication BypassCVE-2021-33766Identify critical remote vulnerabilitiesHighSource
Microsoft Exchange Admin Center Login Panel - DetectIdentify web-based control panelsInfoSource
Microsoft Exchange Web Service - DetectIdentify web-based control panelsInfoSource
Microsoft SharePoint - List API DisclosureIdentify web-based control panelsLowSource
Microsoft Windows 'HTTP.sys' - Remote Code ExecutionCVE-2015-1635Identify critical remote vulnerabilitiesCriticalSource
Microweber <1.1.20 - Information DisclosureCVE-2020-13405Identify critical remote vulnerabilitiesHighSource
MikroTik Router OS Login Panel - DetectIdentify web-based control panelsInfoSource
MikroTik RouterOS Admin Login Panel - DetectIdentify web-based control panelsInfoSource
Milesight Routers - Information DisclosureCVE-2023-43261Identify critical remote vulnerabilitiesHighSource
MinIO Browser Login Panel - DetectIdentify web-based control panelsInfoSource
MinIO Cluster Deployment - Information DisclosureCVE-2023-28432Identify critical remote vulnerabilitiesHighSource
MinIO Console Login Panel - DetectIdentify web-based control panelsInfoSource
Mingsoft MCMS - SQL InjectionCVE-2022-4375Identify critical remote vulnerabilitiesMediumSource
Mingsoft MCMS 5.2.9 - SQL InjectionCVE-2023-50578Identify critical remote vulnerabilitiesCriticalSource
Mingsoft MCMS v5.2.7 - SQL InjectionCVE-2022-26585Identify critical remote vulnerabilitiesCriticalSource
Minio Default LoginIdentify default logins in web-based control panelsHighSource
Mirantis Kubernetes Engine Panel - DetectIdentify web-based control panelsInfoSource
Mitel 6000 - Default LoginIdentify default logins in web-based control panelsHighSource
Mitel Login Panel - DetectIdentify web-based control panelsInfoSource
Mitel MiCollab - Arbitrary File ReadCVE-2024-55550Identify critical remote vulnerabilitiesLowSource
Mitel MiCollab - Authentication BypassCVE-2024-41713Identify critical remote vulnerabilitiesCriticalSource
Mitel MiCollab - Information Disclosure & Denial of ServiceCVE-2022-26143Identify critical remote vulnerabilitiesCriticalSource
Mitel MiCollab <= 9.8.0.33 - SQL InjectionCVE-2024-35286Identify critical remote vulnerabilitiesCriticalSource
Mitel MiCollab Login Panel - DetectIdentify web-based control panelsInfoSource
Mitel NuPoint Unified Messaging Panel - DetectIdentify web-based control panelsInfoSource
Mobile Management Platform Panel - DetectIdentify web-based control panelsInfoSource
MobileIron Core & Connector <= v10.6 & Sentry <= v9.8 - Remote Code ExecutionCVE-2020-15505Identify critical remote vulnerabilitiesCriticalSource
MobileIron Core - Remote Unauthenticated API AccessCVE-2023-35082Identify critical remote vulnerabilitiesCriticalSource
MobileIron Sentry Panel - DetectIdentify web-based control panelsInfoSource
Mobotix - Default LoginIdentify default logins in web-based control panelsHighSource
Modoboa < 2.1.0 - Improper AuthorizationCVE-2023-2227Identify critical remote vulnerabilitiesCriticalSource
Modoboa Login Panel - DetectIdentify web-based control panelsInfoSource
Molgenis - Default LoginIdentify default logins in web-based control panelsHighSource
MongoDB Ops Manager Login Panel - DetectIdentify web-based control panelsInfoSource
MongoDB Server - Information Disclosure (MongoBleed)Identify critical remote vulnerabilitiesHighSource
Mongoose - NoSQL InjectionCVE-2025-23061Identify critical remote vulnerabilitiesCriticalSource
Monitorr Panel - DetectIdentify web-based control panelsInfoSource
Monsta FTP - DetectIdentify web-based control panelsInfoSource
Monstra Admin Panel - DetectIdentify web-based control panelsInfoSource
Moodle Workplace Login Panel - DetectIdentify web-based control panelsInfoSource
Movable Type Pro Login Panel - DetectIdentify web-based control panelsInfoSource
Multiple Shipping Address Woocommerce < 2.0 - SQL InjectionCVE-2022-0783Identify critical remote vulnerabilitiesCriticalSource
Munin Monitoring Dashboard - ExposureIdentify critical remote vulnerabilitiesMediumSource
MyBB - Full Path DisclosureIdentify critical remote vulnerabilitiesLowSource
MyBB Installation Panel - DetectIdentify web-based control panelsHighSource
MyBB Login Panel - DetectIdentify web-based control panelsInfoSource
MyQ Print Server Panel - DetectIdentify web-based control panelsInfoSource
MyStrom Panel - DetectIdentify web-based control panelsInfoSource
Mystic Stealer Panel - DetectIdentify web-based control panelsInfoSource
N-able N-central < 2024.2 - Authentication Bypass DetectionCVE-2024-28200Identify critical remote vulnerabilitiesCriticalSource
N-central - Authentication BypassIdentify critical remote vulnerabilitiesMediumSource
N-central Login Panel - DetectIdentify web-based control panelsInfoSource
N8n - ConfigIdentify critical remote vulnerabilitiesMediumSource
NAKIVO Backup and Replication Solution - Unauthenticated Arbitrary File ReadCVE-2024-48248Identify critical remote vulnerabilitiesHighSource
NConf Login Panel - DetectIdentify web-based control panelsInfoSource
NETGEAR Routers - Authentication BypassCVE-2017-5521Identify critical remote vulnerabilitiesHighSource
NETGEAR Routers - Remote Code ExecutionCVE-2016-6277Identify critical remote vulnerabilitiesHighSource
NI Web-based Configuration & Monitoring - DetectIdentify web-based control panelsInfoSource
NP Data Cache Panel - DetectIdentify web-based control panelsInfoSource
NPS - Authentication BypassIdentify critical remote vulnerabilitiesHighSource
NPort Web Console Login Panel - DetectIdentify web-based control panelsInfoSource
NS-ASG Application Security Gateway 6.3 - Sql InjectionCVE-2024-2330Identify critical remote vulnerabilitiesMediumSource
NSQ Admin Panel - DetectIdentify web-based control panelsMediumSource
NUUO NVRmini - Remote Command ExecutionCVE-2018-14933Identify critical remote vulnerabilitiesCriticalSource
NZBGet Login Panel - DetectIdentify web-based control panelsInfoSource
Nacos - Information DisclosureIdentify critical remote vulnerabilitiesHighSource
NagVis Login Panel - DetectIdentify web-based control panelsInfoSource
Nagios Default LoginIdentify default logins in web-based control panelsHighSource
Nagios Log Server - DetectIdentify web-based control panelsInfoSource
Nagios Login Panel - DetectIdentify web-based control panelsInfoSource
Nagios XI Default Admin Login - DetectIdentify default logins in web-based control panelsCriticalSource
Nagios XI Login Panel - DetectIdentify web-based control panelsInfoSource
NagiosXI <= 5.4.12 - SQL injectionCVE-2018-10736Identify critical remote vulnerabilitiesHighSource
NagiosXI <= 5.4.12 `commandline.php` SQL injectionCVE-2018-10735Identify critical remote vulnerabilitiesHighSource
NagiosXI <= 5.4.12 logbook.php SQL injectionCVE-2018-10737Identify critical remote vulnerabilitiesHighSource
NagiosXI <= 5.4.12 menuaccess.php - SQL injectionCVE-2018-10738Identify critical remote vulnerabilitiesHighSource
Navicat On-Prem Server Panel - DetectIdentify web-based control panelsInfoSource
Navidrome <=0.54.5 - Authentication Bypass in Subsonic APICVE-2025-27112Identify critical remote vulnerabilitiesMediumSource
Ncast busiFacade - Remote Command ExecutionCVE-2024-0305Identify critical remote vulnerabilitiesMediumSource
Neo4j Browser - DetectIdentify web-based control panelsInfoSource
Neobox Web Server Login Panel - DetectIdentify web-based control panelsInfoSource
NetAlert X - Arbitrary File ReadCVE-2024-48766Identify critical remote vulnerabilitiesCriticalSource
NetMRI < 7.6.1 - Authentication Bypass via Hardcoded CredentialsCVE-2025-32815Identify critical remote vulnerabilitiesMediumSource
NetMRI Unauthenticated SQL Injection via skipjackUsernameCVE-2025-32814Identify critical remote vulnerabilitiesCriticalSource
NetMizer LogManagement System Data - Directory ExposureIdentify critical remote vulnerabilitiesHighSource
NetMizer LogManagement System cmd.php - Remote Code ExecutionIdentify critical remote vulnerabilitiesCriticalSource
NetSUS Server Default LoginIdentify default logins in web-based control panelsHighSource
NetSUS Server Login Panel - DetectIdentify web-based control panelsInfoSource
NetScaler Console - PanelIdentify web-based control panelsInfoSource
NetScaler Console - Sensitive Information DisclosureCVE-2024-6235Identify critical remote vulnerabilitiesHighSource
Netdata Dashboard Panel - DetectIdentify web-based control panelsInfoSource
Netdata Panel - DetectIdentify web-based control panelsInfoSource
Netdisco Admin - Default LoginIdentify default logins in web-based control panelsCriticalSource
Netentsec NS-ICG - Default LoginIdentify default logins in web-based control panelsHighSource
Netflix Conductor UI Panel - DetectIdentify web-based control panelsInfoSource
Netflow Analyzer - Default LoginIdentify default logins in web-based control panelsHighSource
Netflow Analyzer Login - PanelIdentify web-based control panelsInfoSource
Netgear DGN2200 - Improper AuthenticationCVE-2024-57046Identify critical remote vulnerabilitiesHighSource
Netgear WNR614 - Improper AuthenticationIdentify critical remote vulnerabilitiesHighSource
Netgear-WN604 downloadFile.php - Information DisclosureCVE-2024-6646Identify critical remote vulnerabilitiesMediumSource
Netmaker - Hardcoded DNS Secret KeyCVE-2023-32077Identify critical remote vulnerabilitiesHighSource
Netris Dashboard Panel - DetectIdentify web-based control panelsInfoSource
Netsparker Login Panel - DetectIdentify web-based control panelsInfoSource
Network Technologies Inc ENVIROMUX - Default LoginIdentify default logins in web-based control panelsHighSource
Newspaper Theme 6.4–6.7.1 - Privilege EscalationCVE-2016-10972Identify critical remote vulnerabilitiesCriticalSource
Next Terminal - Default LoginIdentify default logins in web-based control panelsHighSource
Next.js Cache PoisoningIdentify critical remote vulnerabilitiesHighSource
NextGEN Gallery <= 3.59 - Missing Authorization to Unauthenticated Information DisclosureCVE-2024-3097Identify critical remote vulnerabilitiesMediumSource
Nextcloud Server - DetectionIdentify web-based control panelsInfoSource
NextcloudPi Login - PanelIdentify web-based control panelsInfoSource
Nexus Default LoginIdentify default logins in web-based control panelsHighSource
Nexus Login Panel - DetectIdentify web-based control panelsInfoSource
Nexus Repository Manager - Anonymous Access EnabledIdentify critical remote vulnerabilitiesMediumSource
Nginx Admin Manager Login Panel - DetectIdentify web-based control panelsInfoSource
Nginx End-of-Life - DetectIdentify web-based control panelsInfoSource
Nginx Proxy Manager - Default LoginIdentify default logins in web-based control panelsHighSource
Nginx Proxy Manager Login Panel - DetectIdentify web-based control panelsInfoSource
Nginx UI Panel - DetectIdentify web-based control panelsInfoSource
Ninja Tables <4.1.9 - Unauthenticated Arbitrary File ReadIdentify critical remote vulnerabilitiesHighSource
NoEscape Login Panel - DetectIdentify web-based control panelsInfoSource
NocoBase - Default LoginIdentify default logins in web-based control panelsHighSource
NocoDB Panel - DetectIdentify web-based control panelsInfoSource
NocoDB version <= 0.106.1 - Arbitrary File ReadCVE-2023-35843Identify critical remote vulnerabilitiesHighSource
Node-Red - Default LoginIdentify default logins in web-based control panelsCriticalSource
Node.js REPL History DisclosureIdentify critical remote vulnerabilitiesLowSource
NodeBB XML-RPC Request xmlrpc.php - XML InjectionCVE-2023-43187Identify critical remote vulnerabilitiesCriticalSource
Nodogsplash - Directory TraversalCVE-2023-39120Identify critical remote vulnerabilitiesHighSource
Nordex Control Wind Farm Portal Login Panel - DetectIdentify web-based control panelsInfoSource
Normhost Backup Server Manager Panel - DetectIdentify web-based control panelsInfoSource
Nortek Linear eMerge E3-Series - SQL InjectionCVE-2022-38627Identify critical remote vulnerabilitiesCriticalSource
Nortek Linear eMerge E3-Series <0.32-08f - Remote Command InjectionCVE-2022-31499Identify critical remote vulnerabilitiesCriticalSource
Nortek Linear eMerge Panel - DetectIdentify web-based control panelsInfoSource
NotificationX <= 2.8.2 - SQL InjectionCVE-2024-1698Identify critical remote vulnerabilitiesCriticalSource
NotificationX Dropshipping < 4.4 - SQL InjectionCVE-2018-25031Identify critical remote vulnerabilitiesCriticalSource
Nozomi Guardian Login Panel - DetectIdentify web-based control panelsInfoSource
Nsfocus - Arbitrary User LoginIdentify critical remote vulnerabilitiesHighSource
Nuxeo Platform Login Panel - DetectIdentify web-based control panelsInfoSource
O2 Router Setup Panel - DetectIdentify web-based control panelsInfoSource
O2OA - Default LoginIdentify default logins in web-based control panelsHighSource
OCS Inventory Login Panel - DetectIdentify web-based control panelsInfoSource
OKIOK S-Filer Portal Login Panel - DetectIdentify web-based control panelsInfoSource
OLT Web Management Interface Login Panel - DetectIdentify web-based control panelsInfoSource
OLYMPIC Banking System Login Panel - DetectIdentify web-based control panelsInfoSource
OPNsense Panel - DetectIdentify web-based control panelsInfoSource
OSASI Login - PanelIdentify web-based control panelsInfoSource
OSASI PLC - Default LoginIdentify default logins in web-based control panelsHighSource
OSNEXUS QuantaStor Manager Panel - DetectIdentify web-based control panelsInfoSource
OTOBO Login Panel - DetectIdentify web-based control panelsInfoSource
OcoMon Login Panel - DetectIdentify web-based control panelsInfoSource
OctoberCMS - Default Admin DiscoveryIdentify default logins in web-based control panelsHighSource
Odoo - Database Manager DiscoveryIdentify web-based control panelsLowSource
Odoo - Panel DetectIdentify web-based control panelsInfoSource
Odoo Apps - Cross-Site Scripting via Prototype PollutionCVE-2021-20086Identify critical remote vulnerabilitiesHighSource
Odoo OpenERP Database Selector Panel - DetectIdentify web-based control panelsInfoSource
Office Web Apps Server Panel - DetectIdentify web-based control panelsInfoSource
OfficeKeeper Admin Login Panel - DetectIdentify web-based control panelsInfoSource
Okta Login Panel - DetectIdentify web-based control panelsInfoSource
Omnia MPX Node Login Panel - DetectIdentify web-based control panelsInfoSource
OneDev Panel - DetectIdentify web-based control panelsInfoSource
OneDev.io < 11.0.9 - Arbitrary File ReadCVE-2024-45309Identify critical remote vulnerabilitiesHighSource
Open Game Panel Login Panel - DetectIdentify web-based control panelsInfoSource
Open Virtualization Userportal & Webadmin Panel DetectionIdentify web-based control panelsInfoSource
Open Web Analytics Login - DetectIdentify web-based control panelsInfoSource
Open WebUI - Default LoginIdentify default logins in web-based control panelsCriticalSource
OpenAM Login Panel - DetectIdentify web-based control panelsInfoSource
OpenBullet 2 - PanelIdentify web-based control panelsInfoSource
OpenCATS - Default LoginIdentify default logins in web-based control panelsHighSource
OpenCATS Login Panel - DetectIdentify web-based control panelsInfoSource
OpenCMS 14 & 15 - Cross Site ScriptingCVE-2023-6379Identify critical remote vulnerabilitiesMediumSource
OpenCart Core 4.0.2.3 'search' - SQL InjectionIdentify critical remote vulnerabilitiesHighSource
OpenCart Login Panel - DetectIdentify web-based control panelsInfoSource
OpenEMR - Default Admin DiscoveryIdentify default logins in web-based control panelsHighSource
OpenEMR Product Registration Panel - DetectIdentify web-based control panelsInfoSource
OpenEdge Login Panel - DetectIdentify web-based control panelsInfoSource
OpenMediaVault - Default LoginIdentify default logins in web-based control panelsHighSource
OpenMetadata - Admin User EnumerationIdentify critical remote vulnerabilitiesMediumSource
OpenObserve Login Panel - DetectIdentify web-based control panelsInfoSource
OpenPLC Webserver v3 - Default LoginIdentify default logins in web-based control panelsHighSource
OpenSIS 7.3 - SQL InjectionCVE-2020-6637Identify critical remote vulnerabilitiesCriticalSource
OpenSIS Login Panel - DetectIdentify web-based control panelsInfoSource
OpenSearch Dashboard Panel - DetectIdentify web-based control panelsInfoSource
OpenSign Login Panel - DetectIdentify web-based control panelsInfoSource
OpenText Content Server Login Panel - DetectIdentify web-based control panelsInfoSource
OpenVPN Admin Login Panel - DetectIdentify web-based control panelsInfoSource
OpenVPN Connect Panel - DetectIdentify web-based control panelsInfoSource
OpenVPN Server Router Management Panel - DetectIdentify web-based control panelsInfoSource
OpenVZ Web Panel Login Panel - DetectIdentify web-based control panelsInfoSource
OpenVas Login Panel - DetectIdentify web-based control panelsInfoSource
OpenX/Revive Adserver Login Panel - DetectIdentify web-based control panelsInfoSource
Openfire Admin Console Login Panel - DetectIdentify web-based control panelsInfoSource
Openfire Administration Console - Authentication BypassCVE-2023-32315Identify critical remote vulnerabilitiesHighSource
Opentwrt Login / Configuration InterfaceIdentify web-based control panelsInfoSource
Opentwrt luCI - Admin Login PageIdentify web-based control panelsInfoSource
Openweb UI Panel - DetectIdentify web-based control panelsInfoSource
Opinio Login Panel - DetectIdentify web-based control panelsInfoSource
Oracle ADF Faces Deserialization of Untrusted Data VulnerabilityCVE-2022-21445Identify critical remote vulnerabilitiesCriticalSource
Oracle Access Management Login Panel - DetectIdentify web-based control panelsInfoSource
Oracle Access Manager - Remote Code ExecutionCVE-2021-35587Identify critical remote vulnerabilitiesCriticalSource
Oracle Agile Product Lifecycle Management (PLM) Incorrect Authorization VulnerabilityCVE-2024-21287Identify critical remote vulnerabilitiesHighSource
Oracle Application Server Panel - DetectIdentify web-based control panelsInfoSource
Oracle Business Intelligence Default LoginIdentify default logins in web-based control panelsHighSource
Oracle Business Intelligence Login Panel - DetectIdentify web-based control panelsInfoSource
Oracle Commerce Business Control Center Login Panel - DetectIdentify web-based control panelsInfoSource
Oracle E-Business Suite 12.2.3–12.2.14 – Remote Code ExecutionCVE-2025-61882Identify critical remote vulnerabilitiesCriticalSource
Oracle E-Business Suite <=12.2 - Authentication BypassCVE-2022-21500Identify critical remote vulnerabilitiesHighSource
Oracle E-Business Suite Login Panel - DetectIdentify web-based control panelsInfoSource
Oracle Forms & Reports RCE (CVE-2012-3152 & CVE-2012-3153)CVE-2012-3153Identify critical remote vulnerabilitiesMediumSource
Oracle Fusion - Directory Traversal/Local File InclusionCVE-2020-14864Identify critical remote vulnerabilitiesHighSource
Oracle Fusion Middleware WebLogic Server Administration Console - Remote Code ExecutionCVE-2020-14883Identify critical remote vulnerabilitiesHighSource
Oracle Identity Manager REST WebServices - Authentication BypassCVE-2025-61757Identify critical remote vulnerabilitiesCriticalSource
Oracle Integrated Lights Out Manager Login Panel - DetectIdentify web-based control panelsInfoSource
Oracle Opera Login - DetectIdentify web-based control panelsInfoSource
Oracle PeopleSoft - Default LoginIdentify default logins in web-based control panelsHighSource
Oracle PeopleSoft Enterprise Login Panel - DetectIdentify web-based control panelsInfoSource
Oracle PeopleSoft Login Panel - DetectIdentify web-based control panelsInfoSource
Oracle Peoplesoft - Unauthenticated File ReadCVE-2023-22047Identify critical remote vulnerabilitiesHighSource
Oracle Retail Xstore Suite - Pre-authenticated Path TraversalCVE-2024-21136Identify critical remote vulnerabilitiesHighSource
Oracle WebLogic Login Panel - DetectIdentify web-based control panelsInfoSource
Oracle WebLogic Server - Remote Code ExecutionCVE-2020-2551Identify critical remote vulnerabilitiesCriticalSource
Oracle WebLogic Server - Remote Command ExecutionCVE-2019-2725Identify critical remote vulnerabilitiesCriticalSource
Oracle WebLogic UDDI Explorer Panel - DetectIdentify web-based control panelsInfoSource
Orchid Core VMS Panel - DetectIdentify web-based control panelsInfoSource
OurMGMT3 Admin Login Panel - DetectIdentify web-based control panelsInfoSource
OutSystems Service Center Login Panel - DetectIdentify web-based control panelsInfoSource
OwnCloud - Phpinfo ConfigurationCVE-2023-49103Identify critical remote vulnerabilitiesCriticalSource
PAHTool Login Panel - DetectIdentify web-based control panelsInfoSource
PAN-OS Management Interface - Path Confusion to Authentication BypassCVE-2025-0108Identify critical remote vulnerabilitiesCriticalSource
PAN-OS Management Panel - DetectIdentify web-based control panelsInfoSource
PAN-OS Management Web Interface - Authentication BypassCVE-2024-0012Identify critical remote vulnerabilitiesCriticalSource
PDF Generator Addon for Elementor Page Builder <= 1.7.5 - Arbitrary File DownloadCVE-2024-9935Identify critical remote vulnerabilitiesHighSource
PDI Intellifuel - Device PageIdentify web-based control panelsLowSource
PHP CGI - Argument InjectionCVE-2024-4577Identify critical remote vulnerabilitiesCriticalSource
PHP LDAP Admin Panel - DetectIdentify web-based control panelsInfoSource
PHP Login System 2.0.1 - Cross-Site ScriptingCVE-2023-38875Identify critical remote vulnerabilitiesMediumSource
PHPCI Configuration Exposure "phpci.yml" ExposureIdentify critical remote vulnerabilitiesInfoSource
PHPGurukul Hospital Management System 4.0 - SQL InjectionCVE-2020-22165Identify critical remote vulnerabilitiesHighSource
PHPIPAM CVE-2023-0678Identify critical remote vulnerabilitiesMediumSource
PHPJabbers Food Delivery Script - SQL InjectionCVE-2023-40748Identify critical remote vulnerabilitiesCriticalSource
PHPJabbers Food Delivery Script v3.0 - SQL InjectionCVE-2023-40749Identify critical remote vulnerabilitiesCriticalSource
PHPJabbers Shuttle Booking Software 1.0 - Cross Site ScriptingCVE-2023-4112Identify critical remote vulnerabilitiesMediumSource
PHPJabbers Taxi Booking 2.0 - Cross Site ScriptingCVE-2023-4116Identify critical remote vulnerabilitiesMediumSource
PHPMailer Panel - DetectIdentify web-based control panelsInfoSource
PRONOTE Login Panel - DetectIdentify web-based control panelsInfoSource
PRTG Network Monitor - Hardcoded CredentialsIdentify default logins in web-based control panelsHighSource
Pair Drop Panel - DetectIdentify web-based control panelsInfoSource
Palo Alto Expedition - Admin Account TakeoverCVE-2024-5910Identify critical remote vulnerabilitiesCriticalSource
Palo Alto Expedition - SQL InjectionCVE-2024-9465Identify critical remote vulnerabilitiesCriticalSource
Palo Alto Expedition Project Login - DetectIdentify web-based control panelsInfoSource
Palo Alto Network PAN-OS - Remote Code ExecutionCVE-2017-15944Identify critical remote vulnerabilitiesCriticalSource
Palo Alto Networks PAN-OS Default LoginIdentify default logins in web-based control panelsHighSource
Pandora FMS Mobile Console Login Panel - DetectIdentify web-based control panelsInfoSource
PaperCut < 22.1.3 - Path TraversalCVE-2023-39143Identify critical remote vulnerabilitiesCriticalSource
PaperCut NG Unauthenticated XMLRPC FunctionalityCVE-2023-4568Identify critical remote vulnerabilitiesMediumSource
Parallels H-Sphere Login Panel - DetectIdentify web-based control panelsInfoSource
Parse Dashboard Login Panel - DetectIdentify web-based control panelsInfoSource
Passbolt Login PanelIdentify web-based control panelsInfoSource
Payroll Management System Web Login Panel - DetectIdentify web-based control panelsInfoSource
Pega Infinity Login Panel - DetectIdentify web-based control panelsInfoSource
Pelco Sarix - Default LoginIdentify default logins in web-based control panelsHighSource
Pentaho Default LoginIdentify default logins in web-based control panelsHighSource
Persis Panel - DetectIdentify web-based control panelsInfoSource
Personal Weather Station Dashboard 12 - Directory TraversalCVE-2025-47423Identify critical remote vulnerabilitiesMediumSource
Phabricator Login Panel - DetectIdentify web-based control panelsInfoSource
Phoenix Contact CHARX SEC-3XXX AC Charging Controller Panel - DetectIdentify web-based control panelsInfoSource
Phoenix Contact CHARX SEC-3XXX AC Charging Controller REST API - DetectIdentify critical remote vulnerabilitiesInfoSource
Phoenix Contact CHARX SEC-3XXX AC Controller < 1.7.3 - Multiple VulnerabilitiesIdentify critical remote vulnerabilitiesCriticalSource
Phoronix Test Suite Panel - DetectIdentify web-based control panelsInfoSource
Photo Gallery by 10Web < 1.6.0 - SQL InjectionCVE-2022-0169Identify critical remote vulnerabilitiesCriticalSource
PhotoPrism Panel - DetectIdentify web-based control panelsInfoSource
PhpMyAdmin - Unauthenticated AccessIdentify critical remote vulnerabilitiesHighSource
PhpMyAdmin Scripts - Remote Code ExecutionCVE-2009-1151Identify critical remote vulnerabilitiesCriticalSource
Pichome 2.1.0 - Arbitrary File ReadCVE-2025-1743Identify critical remote vulnerabilitiesMediumSource
Pichome Login Panel - DetectIdentify web-based control panelsInfoSource
Piwigo Login Panel - DetectIdentify web-based control panelsInfoSource
Planet eStream Login Panel - DetectIdentify web-based control panelsInfoSource
Plausible Panel - DetectIdentify web-based control panelsInfoSource
Plesk Login Panel - DetectIdentify web-based control panelsInfoSource
Plesk Obsidian Login Panel - DetectIdentify web-based control panelsInfoSource
PocketBase Panel - DetectIdentify web-based control panelsInfoSource
Polarion Siemens Login - PanelIdentify web-based control panelsInfoSource
Popup-Maker < 1.8.12 - Broken AuthenticationCVE-2019-17574Identify critical remote vulnerabilitiesCriticalSource
Portainer - Init Deploy DiscoveryIdentify critical remote vulnerabilitiesMediumSource
Portainer Login Panel - DetectIdentify web-based control panelsInfoSource
Post Grid <= 2.2.50 - Information Exposure via REST APICVE-2023-40211Identify critical remote vulnerabilitiesHighSource
PostHog Login Panel - DetectIdentify web-based control panelsInfoSource
Poste.io Admin Panel - DetectIdentify web-based control panelsInfoSource
PowerChute Network Shutdown Panel - DetectIdentify web-based control panelsInfoSource
PowerCom Network ManagerIdentify web-based control panelsInfoSource
PowerJob - Default LoginIdentify default logins in web-based control panelsHighSource
PowerJob <=4.3.2 - Unauthenticated AccessCVE-2023-29923Identify critical remote vulnerabilitiesMediumSource
PowerJob Login Panel - DetectIdentify web-based control panelsInfoSource
PowerShell Universal - Default LoginIdentify default logins in web-based control panelsHighSource
Powertek Firmware <3.30.30 - Authorization BypassCVE-2022-33174Identify critical remote vulnerabilitiesCriticalSource
PrestaShop Theme Volty CMS Blog - SQL InjectionCVE-2023-39650Identify critical remote vulnerabilitiesCriticalSource
PrestaShop `tshirtecommerce` Module - SQL InjectionCVE-2023-27637Identify critical remote vulnerabilitiesCriticalSource
PrestaShop fieldpopupnewsletter Module - Cross Site ScriptingCVE-2023-39676Identify critical remote vulnerabilitiesMediumSource
PrestaShop productsalert - SQL InjectionCVE-2024-36683Identify critical remote vulnerabilitiesHighSource
PrestaShop xipblog - SQL InjectionCVE-2023-27847Identify critical remote vulnerabilitiesCriticalSource
Prestashop posstaticfooter <= 1.0.0 - SQL InjectionCVE-2023-30194Identify critical remote vulnerabilitiesCriticalSource
Prettier - Ignore File DisclosureIdentify critical remote vulnerabilitiesInfoSource
Prime Mover < 1.9.3 - Sensitive Data ExposureCVE-2023-6505Identify critical remote vulnerabilitiesHighSource
Primetek Primefaces 5.x - Remote Code ExecutionCVE-2017-1000486Identify critical remote vulnerabilitiesCriticalSource
Prison Management System - SQL Injection Authentication BypassCVE-2024-33288Identify critical remote vulnerabilitiesHighSource
Pritunl - PanelIdentify web-based control panelsInfoSource
PrivateGPT - DetectIdentify web-based control panelsInfoSource
ProcessWire Login - Panel DetectIdentify web-based control panelsInfoSource
Procore Login - PanelIdentify web-based control panelsInfoSource
Progress Kemp LoadMaster - Command InjectionCVE-2024-1212Identify critical remote vulnerabilitiesCriticalSource
Progress Kemp LoadMaster Panel - DetectIdentify web-based control panelsInfoSource
Project Insight Login Panel - DetectIdentify web-based control panelsInfoSource
ProjectSend Login Panel - DetectIdentify web-based control panelsInfoSource
Proofpoint Protection Server Panel - DetectIdentify web-based control panelsInfoSource
Protect WP Admin < 4.0 - Unauthenticated Protection BypassCVE-2023-3139Identify critical remote vulnerabilitiesMediumSource
Proxmox Virtual Environment Login Panel - DetectIdentify web-based control panelsInfoSource
Pterodactyl Panel - Remote Code ExecutionCVE-2025-49132Identify critical remote vulnerabilitiesCriticalSource
Pterodactyl game server - PanelIdentify web-based control panelsInfoSource
Pulsar Admin Console Panel - DetectIdentify web-based control panelsInfoSource
Pulsar Admin UI Panel - DetectIdentify web-based control panelsInfoSource
Pulsar360 Admin Panel - DetectIdentify web-based control panelsInfoSource
Pulse Connect Secure SSL VPN Arbitrary File ReadCVE-2019-11510Identify critical remote vulnerabilitiesCriticalSource
Puppetboard Panel - DetectIdentify web-based control panelsInfoSource
Pure Storage Login Panel - DetectIdentify web-based control panelsInfoSource
PyLoad Default LoginIdentify default logins in web-based control panelsHighSource
PyLoad Login - PanelIdentify web-based control panelsInfoSource
Python Requirements File DisclosureIdentify critical remote vulnerabilitiesLowSource
Python Setup Configuration - ExposureIdentify critical remote vulnerabilitiesLowSource
QNAP HBS 3 - Broken Access ControlCVE-2021-28799Identify critical remote vulnerabilitiesCriticalSource
QNAP Music Station < 5.4.0 - Authentication BypassCVE-2023-45038Identify critical remote vulnerabilitiesMediumSource
QNAP Photo Station - Path TraversalCVE-2019-7195Identify critical remote vulnerabilitiesCriticalSource
QNAP Photo Station Panel - DetectIdentify web-based control panelsInfoSource
QNAP QTS Photo Station External Reference - Local File InclusionCVE-2022-27593Identify critical remote vulnerabilitiesCriticalSource
QNAP QTS and Photo Station 6.0.3 - Remote Command ExecutionCVE-2019-7192Identify critical remote vulnerabilitiesCriticalSource
QNAP Turbo NAS Login Panel - DetectIdentify web-based control panelsInfoSource
Qlik Sense Enterprise - HTTP Request SmugglingCVE-2023-41265Identify critical remote vulnerabilitiesCriticalSource
Qlik Sense Enterprise - Path TraversalCVE-2023-41266Identify critical remote vulnerabilitiesHighSource
Qlik Sense Server Panel - DetectIdentify web-based control panelsInfoSource
QlikView AccessPoint Login Panel - DetectIdentify web-based control panelsInfoSource
QloApps 1.6.0 - SQL InjectionCVE-2023-36284Identify critical remote vulnerabilitiesHighSource
QmailAdmin Login Panel - DetectIdentify web-based control panelsInfoSource
Qualitor ITSM - DetectIdentify web-based control panelsInfoSource
Quest KACE System Management Appliance 8.0.318 - Remote Code ExecutionCVE-2018-11138Identify critical remote vulnerabilitiesCriticalSource
Quest Modem Configuration Login - PanelIdentify web-based control panelsInfoSource
Quick.CMS v6.7 - SQL InjectionIdentify critical remote vulnerabilitiesHighSource
Quilium Panel - DetectIdentify web-based control panelsInfoSource
RCDevs WebADM Panel - DetectIdentify web-based control panelsInfoSource
RD Web Access Panel - DetectIdentify web-based control panelsInfoSource
RDWeb RemoteApp and Desktop Connections - Web AccessIdentify web-based control panelsInfoSource
RG-UAC Ruijie - Password Hashes LeakIdentify critical remote vulnerabilitiesHighSource
RStudio Sign In Panel - DetectIdentify web-based control panelsInfoSource
RWS WorldServer - Authentication BypassCVE-2022-34267Identify critical remote vulnerabilitiesCriticalSource
RabbitMQ Default LoginIdentify default logins in web-based control panelsHighSource
Racksnet Login Panel - DetectIdentify web-based control panelsInfoSource
RaidenMAILD Mail Server v.4.9.4 - Path TraversalCVE-2024-32399Identify critical remote vulnerabilitiesHighSource
Rainloop WebMail - Default Admin LoginIdentify default logins in web-based control panelsHighSource
Rancher Dashboard Panel - DetectIdentify web-based control panelsInfoSource
Rancher Default LoginIdentify default logins in web-based control panelsHighSource
Rancher Login Panel - DetectIdentify web-based control panelsInfoSource
Rapid7 Nexpose VM Security Console - DetectIdentify web-based control panelsInfoSource
RaspAP 2.8.7 - Unauthenticated Command InjectionCVE-2022-39986Identify critical remote vulnerabilitiesCriticalSource
RaspberryMatic Login Panel - DetectIdentify web-based control panelsInfoSource
Ray API - Local File InclusionCVE-2023-6021Identify critical remote vulnerabilitiesHighSource
Ray Static File - Local File InclusionCVE-2023-6020Identify critical remote vulnerabilitiesHighSource
ReCrystallize Server - Authentication BypassCVE-2024-26331Identify critical remote vulnerabilitiesHighSource
React Server Components - Remote Code ExecutionCVE-2025-55182Identify critical remote vulnerabilitiesCriticalSource
Really Simple Security < 9.1.2 - Authentication BypassCVE-2024-10924Identify critical remote vulnerabilitiesCriticalSource
Red Hat JBoss Enterprise Application Platform - Sensitive Information DisclosureCVE-2010-1429Identify critical remote vulnerabilitiesMediumSource
Red Hat Satellite Panel - DetectIdentify web-based control panelsInfoSource
Redash Login Panel - DetectIdentify web-based control panelsInfoSource
Redash Setup Configuration - Default Secrets DisclosureCVE-2021-41192Identify critical remote vulnerabilitiesHighSource
Redis Commander - Default LoginIdentify default logins in web-based control panelsHighSource
Redis Enterprise - DetectIdentify web-based control panelsInfoSource
Redis Sandbox Escape - Remote Code ExecutionCVE-2022-0543Identify critical remote vulnerabilitiesCriticalSource
Redmine Login Panel - DetectIdentify web-based control panelsInfoSource
Regify Login Panel - DetectIdentify web-based control panelsInfoSource
Registrations for the Events Calendar < 2.7.6 - SQL InjectionCVE-2021-24943Identify critical remote vulnerabilitiesCriticalSource
RemKon Device Manager Login Panel - DetectIdentify web-based control panelsInfoSource
Remedy Axis Login Panel - DetectIdentify web-based control panelsInfoSource
Reolink E1 Zoom Camera <=3.0.0.716 - Information DisclosureCVE-2021-40150Identify critical remote vulnerabilitiesHighSource
Reolink E1 Zoom Camera <=3.0.0.716 - Private Key DisclosureCVE-2021-40149Identify critical remote vulnerabilitiesMediumSource
Reolink Panel - DetectIdentify web-based control panelsInfoSource
Repetier Server - Directory TraversalCVE-2023-31059Identify critical remote vulnerabilitiesHighSource
Repetier Server Panel - DetectIdentify web-based control panelsInfoSource
Reportico Administration Page - DetectIdentify web-based control panelsInfoSource
Reposilite >= 3.3.0, < 3.5.12 - Arbitrary File ReadCVE-2024-36117Identify critical remote vulnerabilitiesHighSource
Reposilite Login Panel - DetectIdentify web-based control panelsInfoSource
Reprise License Manager 14.2 - Authentication BypassCVE-2021-44152Identify critical remote vulnerabilitiesCriticalSource
Reprise License Manager 14.2 - Information DisclosureCVE-2022-28365Identify critical remote vulnerabilitiesMediumSource
Request Tracker - PanelIdentify web-based control panelsInfoSource
Residential Gateway Login Panel - DetectIdentify web-based control panelsInfoSource
Retool Login Panel - DetectIdentify web-based control panelsInfoSource
RevPi Webstatus <= v2.4.5 - Authentication BypassCVE-2025-41646Identify critical remote vulnerabilitiesCriticalSource
Revive Adserver 4.2 - Remote Code ExecutionCVE-2019-5434Identify critical remote vulnerabilitiesCriticalSource
Ricoh Web Image Monitor - DetectIdentify web-based control panelsInfoSource
Ricoh Web Image Monitor - Reflected XSSCVE-2025-41393Identify critical remote vulnerabilitiesMediumSource
Riello Netman 204 - SQL InjectionCVE-2024-8877Identify critical remote vulnerabilitiesCriticalSource
Riello UPS NetMan 204 Network Card - Default LoginIdentify default logins in web-based control panelsHighSource
Riello UPS NetMan 204 Panel - DetectIdentify web-based control panelsInfoSource
RiteCMS - Default LoginIdentify default logins in web-based control panelsHighSource
Rocket.Chat <=3.13 - NoSQL InjectionCVE-2021-22911Identify critical remote vulnerabilitiesCriticalSource
RocketChat Login Panel - DetectIdentify web-based control panelsInfoSource
Rockmongo Default LoginIdentify default logins in web-based control panelsHighSource
Roxy File Manager - Panel DetectIdentify web-based control panelsInfoSource
Roxy-WI - Remote Code ExecutionCVE-2022-31126Identify critical remote vulnerabilitiesCriticalSource
Roxy-WI < 6.1.1.0 - Remote Code ExecutionCVE-2022-31137Identify critical remote vulnerabilitiesCriticalSource
Ruckus Wireless - Default LoginIdentify default logins in web-based control panelsCriticalSource
Ruckus Wireless Admin Login Panel - DetectIdentify web-based control panelsInfoSource
Ruckus Wireless Unleashed Login Panel - DetectIdentify web-based control panelsInfoSource
Ruijie NBR Series Routers - Default LoginIdentify default logins in web-based control panelsHighSource
Ruijie RG-EG - Remote Code ExecutionIdentify critical remote vulnerabilitiesCriticalSource
Ruijie RG-EW1200G Router Background - Login BypassCVE-2023-4415Identify critical remote vulnerabilitiesHighSource
Ruijie RG-NBS2009G-P - Improper AuthenticationCVE-2024-24116Identify critical remote vulnerabilitiesCriticalSource
Ruijie RG-UAC Login Panel - DetectIdentify web-based control panelsInfoSource
Rundeck - Default LoginIdentify default logins in web-based control panelsHighSource
Rundeck Login Panel - DetectIdentify web-based control panelsInfoSource
Rustici Content Controller Panel - DetectIdentify web-based control panelsInfoSource
SAP Analytics Cloud Panel - DetectIdentify web-based control panelsInfoSource
SAP Memory Pipes (MPI) DesynchronizationCVE-2022-22536Identify critical remote vulnerabilitiesCriticalSource
SAP NetWeaver - Backdoor DetectionIdentify critical remote vulnerabilitiesCriticalSource
SAP NetWeaver Application Server Java 7.5 - Local File InclusionCVE-2017-12637Identify critical remote vulnerabilitiesHighSource
SAP NetWeaver Composition Environment Tools - DetectIdentify web-based control panelsInfoSource
SAP NetWeaver SQL Injection VulnerabilityCVE-2016-2386Identify critical remote vulnerabilitiesCriticalSource
SAP Solution Manager 7.2 - Remote Command ExecutionCVE-2020-6207Identify critical remote vulnerabilitiesCriticalSource
SAP SuccessFactors Login Panel - DetectIdentify web-based control panelsInfoSource
SAS Login Panel - DetectIdentify web-based control panelsInfoSource
SAUTER moduWeb Vision Panel - DetectIdentify web-based control panelsInfoSource
SEH utnserver Pro/ProMAX/INU-100 20.1.22 - Cross-Site ScriptingCVE-2024-5420Identify critical remote vulnerabilitiesHighSource
SGP Login Panel - DetectIdentify web-based control panelsInfoSource
SHOUTcast Server Panel - DetectIdentify web-based control panelsInfoSource
SKYSEA Client View Panel - DetectIdentify web-based control panelsInfoSource
SOPlanning - Default LoginIdentify default logins in web-based control panelsHighSource
SOUND4 IMPACT/FIRST/PULSE/Eco <= 2.x - Authentication BypassIdentify critical remote vulnerabilitiesHighSource
SOUND4 IMPACT/FIRST/PULSE/Eco <=2.x (PHPTail) Unauthenticated File DisclosureIdentify critical remote vulnerabilitiesMediumSource
SPIP - Remote Command ExecutionCVE-2023-27372Identify critical remote vulnerabilitiesCriticalSource
SQL Buddy Login Panel - DetectIdentify web-based control panelsInfoSource
SQL Monitor - DiscoveryIdentify web-based control panelsInfoSource
SSH PrivX Login Panel - DetectIdentify web-based control panelsInfoSource
STAGIL Navigation for Jira Menu & Themes <2.0.52 - Local File InclusionCVE-2023-26256Identify critical remote vulnerabilitiesHighSource
STAGIL Navigation for Jira Menu & Themes <2.0.52 - Local File InclusionCVE-2023-26255Identify critical remote vulnerabilitiesHighSource
SUNGROW Logger1000 Panel - DetectIdentify web-based control panelsInfoSource
SUSE Manager Server - PanelIdentify web-based control panelsInfoSource
SafeNet Authentication Login Panel - DetectIdentify web-based control panelsInfoSource
Sage X3 Login Panel - DetectIdentify web-based control panelsInfoSource
Saia PCD Web Server Panel - DetectIdentify web-based control panelsInfoSource
SaltStack <=3002 - Shell InjectionCVE-2020-16846Identify critical remote vulnerabilitiesCriticalSource
SaltStack Config Panel - DetectIdentify web-based control panelsInfoSource
Samsung MagicINFO Panel - DetectIdentify web-based control panelsInfoSource
Samsung Printer - Default LoginIdentify default logins in web-based control panelsHighSource
Sanity Studio Panel - DetectIdentify web-based control panelsInfoSource
Sante PACS Server.exe - Path Traversal Information DisclosureCVE-2025-2264Identify critical remote vulnerabilitiesHighSource
Satellian Intellian Aptus Web <= 1.24 - Remote Command ExecutionCVE-2020-7980Identify critical remote vulnerabilitiesCriticalSource
Satis Composer Repository - DetectIdentify web-based control panelsInfoSource
Sato - Default LoginIdentify default logins in web-based control panelsHighSource
SawtoothSoftware Lighthouse Studio < 9.16.14 - Pre-Auth Remote Code ExecutionCVE-2025-34300Identify critical remote vulnerabilitiesCriticalSource
Scan2Net - PanelIdentify web-based control panelsInfoSource
Schneider Electric Pelco VideoXpert Enterprise 2.0 - Path TraversalCVE-2017-9965Identify critical remote vulnerabilitiesMediumSource
Scribble Diffusion Panel - DetectIdentify web-based control panelsInfoSource
ScriptCase Panel DetectIdentify web-based control panelsInfoSource
ScriptCase Production Environment LoginIdentify web-based control panelsInfoSource
Seafile Panel - DetectIdentify web-based control panelsInfoSource
Seagate NAS Login - DetectIdentify web-based control panelsInfoSource
Seagate NAS OS 4.3.15.1 - Server Information DisclosureCVE-2018-12296Identify critical remote vulnerabilitiesHighSource
SecurEnvoy Login Panel - DetectIdentify web-based control panelsInfoSource
SecurEnvoy Two Factor Authentication - LDAP InjectionCVE-2024-37393Identify critical remote vulnerabilitiesHighSource
Secure Login Service Login Panel - DetectIdentify web-based control panelsInfoSource
SecurePoint UTM 12.x Session ID LeakCVE-2023-22620Identify critical remote vulnerabilitiesHighSource
Securepoint UTM - Leaking Remote Memory ContentsCVE-2023-22897Identify critical remote vulnerabilitiesMediumSource
Security Onion Panel - DetectIdentify web-based control panelsInfoSource
SecuritySpy Camera Panel - DetectIdentify web-based control panelsInfoSource
SeedDMS - Default LoginIdentify default logins in web-based control panelsHighSource
SeedDMS Login Panel - DetectIdentify web-based control panelsInfoSource
Seeyon OA A6 setextno.jsp - SQL InjectionIdentify critical remote vulnerabilitiesHighSource
Selenium Grid Panel - DetectIdentify web-based control panelsInfoSource
SelfCheck System Manager - PanelIdentify web-based control panelsInfoSource
Sensei LMS < 4.24.2 - Email Template LeakCVE-2024-7786Identify critical remote vulnerabilitiesMediumSource
Sensu by Sumo Logic Login Panel - DetectIdentify web-based control panelsInfoSource
SentinelOne Management Console Login Panel - DetectIdentify web-based control panelsInfoSource
Sentry Login PanelIdentify web-based control panelsInfoSource
SequoiaDB Login Panel - DetectIdentify web-based control panelsInfoSource
Server Backup Manager SE Panel - DetectIdentify web-based control panelsInfoSource
ServiceNow - Incomplete Input ValidationCVE-2024-5217Identify critical remote vulnerabilitiesCriticalSource
ServiceNow Login Panel - DetectIdentify web-based control panelsInfoSource
ServiceNow UI Macros - Template InjectionCVE-2024-4879Identify critical remote vulnerabilitiesCriticalSource
SevOne NMS Network ManagerIdentify web-based control panelsInfoSource
ShardingSphere ElasticJob UI PanelIdentify web-based control panelsInfoSource
Sharefile Login - PanelIdentify web-based control panelsInfoSource
Shell In A Box - DetectIdentify web-based control panelsInfoSource
Shield Security WP Plugin <= 18.5.9 - Local File InclusionCVE-2023-6989Identify critical remote vulnerabilitiesCriticalSource
Shiziyu CMS Api Controller - SQL InjectionIdentify critical remote vulnerabilitiesHighSource
ShokoServer System - Local File Inclusion (LFI)CVE-2023-43662Identify critical remote vulnerabilitiesHighSource
ShortPixel Adaptive Images < 3.6.3 - Cross Site ScriptingCVE-2023-0334Identify critical remote vulnerabilitiesMediumSource
Sidekiq < 7.0.8 - Cross-Site ScriptingCVE-2023-1892Identify critical remote vulnerabilitiesCriticalSource
Sidekiq Dashboard Panel - DetectIdentify web-based control panelsMediumSource
Siemens SIMATIC HMI Miniweb - Default LoginIdentify default logins in web-based control panelsHighSource
Signet Explorer Dashboard - DetectIdentify web-based control panelsInfoSource
SimpleHelp <= 5.5.7 - Unauthenticated Path TraversalCVE-2024-57727Identify critical remote vulnerabilitiesHighSource
Sitecore - Remote Code ExecutionCVE-2023-35813Identify critical remote vulnerabilitiesCriticalSource
Sitecore CMS - Cross-Site ScriptingCVE-2014-100004Identify critical remote vulnerabilitiesMediumSource
Sitecore Experience Manager (XM) and Experience Platform (XP) - Hardcoded CredentialsCVE-2025-34509Identify critical remote vulnerabilitiesHighSource
Sitecore Experience Platform <= 10.4 - Arbitrary File ReadCVE-2024-46938Identify critical remote vulnerabilitiesHighSource
Sitecore Login Panel - DetectIdentify web-based control panelsInfoSource
Skeepers Login Panel - DetectIdentify web-based control panelsInfoSource
Smart s200 Management Platform v.S200 - SQL InjectionCVE-2024-27718Identify critical remote vulnerabilitiesHighSource
SmartPing Dashboard Panel - DetectIdentify web-based control panelsInfoSource
SmartSearchWP < 2.4.6 - OpenAI Key DisclosureIdentify critical remote vulnerabilitiesMediumSource
Social Auto Poster <= 5.3.14 - Stored Cross-Site ScriptingCVE-2024-6753Identify critical remote vulnerabilitiesHighSource
SoftEther VPN Admin Console - Default LoginIdentify default logins in web-based control panelsHighSource
SoftEther VPN Panel - DetectIdentify web-based control panelsInfoSource
SolarView 6.00 - Remote Command ExecutionCVE-2022-40881Identify critical remote vulnerabilitiesCriticalSource
SolarView Compact 6.00 - OS Command InjectionCVE-2022-29303Identify critical remote vulnerabilitiesCriticalSource
SolarView Compact 6.00 - OS Command InjectionCVE-2023-23333Identify critical remote vulnerabilitiesCriticalSource
SolarView Compact <= 6.00 - Local File InclusionCVE-2023-29919Identify critical remote vulnerabilitiesCriticalSource
SolarView Compact Panel - DetectIdentify web-based control panelsInfoSource
SolarWinds ARM (Access Rights Manager) - DetectIdentify web-based control panelsInfoSource
SolarWinds Orion - Default LoginIdentify default logins in web-based control panelsHighSource
SolarWinds Orion API - Auth BypassCVE-2020-10148Identify critical remote vulnerabilitiesCriticalSource
SolarWinds Security Event Manager - Unauthenticated RCECVE-2024-0692Identify critical remote vulnerabilitiesHighSource
SolarWinds Serv-U - Directory TraversalCVE-2024-28995Identify critical remote vulnerabilitiesHighSource
SolarWinds Web Help Desk - Hardcoded CredentialCVE-2024-28987Identify critical remote vulnerabilitiesCriticalSource
SolarWinds Web Help Desk < 12.8.3 - Insecure DeserializationCVE-2024-28986Identify critical remote vulnerabilitiesCriticalSource
Solara <1.35.1 - Local File InclusionCVE-2024-39903Identify critical remote vulnerabilitiesHighSource
Somansa DLP Login Panel - DetectIdentify web-based control panelsInfoSource
SonarQube - Default LoginIdentify default logins in web-based control panelsHighSource
Sonatype Nexus Repository Manager <3.15.0 - Remote Code ExecutionCVE-2019-7238Identify critical remote vulnerabilitiesCriticalSource
Sonatype Nexus Repository Manager 3 - Local File InclusionCVE-2024-4956Identify critical remote vulnerabilitiesHighSource
Sonatype Nexus Repository Manager 3 - Remote Code ExecutionCVE-2020-10199Identify critical remote vulnerabilitiesHighSource
SonicOS SSLVPN Authentication Bypass VulnerabilityCVE-2024-53704Identify critical remote vulnerabilitiesCriticalSource
SonicWall Analyzer Login Panel - DetectIdentify web-based control panelsInfoSource
SonicWall Appliance Management Console Login Panel - DetectIdentify web-based control panelsInfoSource
SonicWall GMS and Analytics - SQL InjectionCVE-2023-34133Identify critical remote vulnerabilitiesHighSource
SonicWall Network Security Login - DetectIdentify web-based control panelsInfoSource
SonicWall SMA1000 LFICVE-2023-0126Identify critical remote vulnerabilitiesHighSource
Sonicwall - Pre-Authentication Arbitrary File ReadCVE-2024-38475Identify critical remote vulnerabilitiesCriticalSource
Sophos Firewall <=18.5 MR3 - Remote Code ExecutionCVE-2022-1040Identify critical remote vulnerabilitiesCriticalSource
Sophos Firewall Login Panel - DetectIdentify web-based control panelsInfoSource
Sophos Mobile Panel - DetectIdentify web-based control panelsInfoSource
Sophos Web ApplianceIdentify web-based control panelsInfoSource
Sound4 IMPACT/FIRST/PULSE/Eco <=2.x - Authentication BypassIdentify critical remote vulnerabilitiesHighSource
SpaceLogic C-Bus Home Panel - DetectIdentify web-based control panelsInfoSource
Spam protection, AntiSpam, FireWall by CleanTalk < 5.153.4 - Unauthenticated Blind SQL InjectionCVE-2021-24295Identify critical remote vulnerabilitiesHighSource
Speedtest Panel - DetectionIdentify web-based control panelsInfoSource
SphinxOnline Panel - DetectIdentify web-based control panelsInfoSource
Splunk - Default LoginIdentify default logins in web-based control panelsHighSource
Splunk Enterprise - Local File InclusionCVE-2024-36991Identify critical remote vulnerabilitiesHighSource
Splunk Enterprise Login Panel - DetectIdentify web-based control panelsInfoSource
Splunk SOAR Login Panel - DetectIdentify web-based control panelsInfoSource
SpotWeb Login Panel - DetectIdentify web-based control panelsInfoSource
Spotweb <= 1.5.1 - Cross Site Scripting (Reflected)CVE-2021-43725Identify critical remote vulnerabilitiesMediumSource
Spring Cloud Config Server - Local File InclusionCVE-2020-5410Identify critical remote vulnerabilitiesHighSource
SqWebMail Login Panel - DetectIdentify web-based control panelsInfoSource
Squidex Headless CMS Panel - DetectIdentify web-based control panelsInfoSource
SquirrelMail Login Panel - DetectIdentify web-based control panelsInfoSource
Stackposts Social Marketing Tool v1.0 - SQL InjectionIdentify critical remote vulnerabilitiesHighSource
Star Micronics Network Utility Panel - DetectIdentify web-based control panelsInfoSource
Stash < 0.26.0 - SQL InjectionCVE-2024-32231Identify critical remote vulnerabilitiesMediumSource
SteVe Login Panel - DetectIdentify web-based control panelsInfoSource
SteVe OCPP server - Default LoginIdentify default logins in web-based control panelsInfoSource
Stirling PDF Panel - DetectIdentify web-based control panelsInfoSource
Stock Ticker <= 3.23.2 - Cross-Site ScriptingCVE-2023-40208Identify critical remote vulnerabilitiesHighSource
Stop User Enumeration WordPress plugin - Authentication BypassCVE-2025-4302Identify critical remote vulnerabilitiesMediumSource
Storybook Panel - DetectIdentify web-based control panelsInfoSource
Strapi Login Panel - DetectIdentify web-based control panelsInfoSource
Strider CD Panel - DetectIdentify web-based control panelsInfoSource
Structurizr - Default LoginIdentify default logins in web-based control panelsHighSource
Structurizr Panel - DetectIdentify web-based control panelsInfoSource
SugarCRM Login Panel - DetectIdentify web-based control panelsInfoSource
SuiteCRM - SQL InjectionCVE-2024-36412Identify critical remote vulnerabilitiesCriticalSource
Sunbird DCIM - DetectIdentify web-based control panelsInfoSource
SuperAdmin Login Panel - DetectIdentify web-based control panelsInfoSource
SuperWebmailer 7.21.0.01526 - Remote Code ExecutionCVE-2020-11546Identify critical remote vulnerabilitiesCriticalSource
Supermicro BMC Login Panel - DetectIdentify web-based control panelsInfoSource
Supermicro IPMI - Default LoginIdentify default logins in web-based control panelsHighSource
Supershell - Default LoginIdentify default logins in web-based control panelsHighSource
Supertokens Login Panel - DetectIdentify web-based control panelsInfoSource
SupportCandy < 2.2.7 - Reflected Cross-Site ScriptingCVE-2021-24878Identify critical remote vulnerabilitiesMediumSource
Suprema BioStar 2 Panel - DetectIdentify web-based control panelsInfoSource
Swift Performance Lite < 2.3.7.2 - Local PHP File InclusionCVE-2024-10516Identify critical remote vulnerabilitiesHighSource
Syfadis Xperience Login Panel - DetectIdentify web-based control panelsInfoSource
Symantec Data Loss Prevention Login Panel - DetectIdentify web-based control panelsInfoSource
Symantec Encryption Server Login Panel - DetectIdentify web-based control panelsInfoSource
Symantec Endpoint Protection Manager Login Panel - DetectIdentify web-based control panelsInfoSource
Symantec PGP Global Directory Panel - DetectIdentify web-based control panelsInfoSource
Symfony Profiler - Remote Access via Injected ArgumentsCVE-2024-50340Identify critical remote vulnerabilitiesHighSource
Symmetricom SyncServer Panel - DetectIdentify web-based control panelsInfoSource
Symmetricom SyncServer Unauthenticated - Remote Command ExecutionCVE-2022-40022Identify critical remote vulnerabilitiesCriticalSource
Synacor Zimbra Collaboration <8.7.11p10 - XML External Entity InjectionCVE-2019-9670Identify critical remote vulnerabilitiesCriticalSource
Synapse Mobility Login Panel - DetectIdentify web-based control panelsInfoSource
SyncThru Web Service Panel - DetectIdentify web-based control panelsInfoSource
Synopsys Coverity PanelIdentify web-based control panelsInfoSource
SysAid Login Panel - DetectIdentify web-based control panelsInfoSource
T-Up OpenFrameIdentify web-based control panelsInfoSource
TIBCO JasperReports Library - Directory TraversalCVE-2018-18809Identify critical remote vulnerabilitiesMediumSource
TIBCO Jaspersoft Login Panel - DetectIdentify web-based control panelsInfoSource
TIBCO Managed File Transfer - PanelIdentify web-based control panelsInfoSource
TOTOLINK A3002RU 1.0.8 - Information DisclosureCVE-2018-13317Identify critical remote vulnerabilitiesMediumSource
TOTOLINK A3700R - Command InjectionCVE-2023-46574Identify critical remote vulnerabilitiesCriticalSource
TOTOLINK CP450 v4.1.0cu.747_B20191224 - Hard-Coded Password VulnerabilityCVE-2024-7332Identify critical remote vulnerabilitiesCriticalSource
TOTOLINK CX-A3002RU - Remote Code ExecutionCVE-2024-51228Identify critical remote vulnerabilitiesMediumSource
TOTOLINK EX1200T 4.1.2cu.5215 - Authentication BypassCVE-2021-42887Identify critical remote vulnerabilitiesCriticalSource
TOTOLINK EX1800T TOTOLINK EX1800T - Command InjectionCVE-2024-34257Identify critical remote vulnerabilitiesCriticalSource
TOTOLINK N150RT - Password ExposureIdentify critical remote vulnerabilitiesHighSource
TOTOLINK/Realtek Routers - CAPTCHA BypassCVE-2019-19825Identify critical remote vulnerabilitiesCriticalSource
TOTOLINK/Realtek Routers - Information DisclosureCVE-2019-19822Identify critical remote vulnerabilitiesHighSource
TOTOLINK/Realtek Routers - Information DisclosureCVE-2019-19823Identify critical remote vulnerabilitiesHighSource
TOTOLink Router - Remote Command ExecutionIdentify critical remote vulnerabilitiesCriticalSource
TP-LINK - Local File InclusionCVE-2015-3035Identify critical remote vulnerabilitiesHighSource
TP-LINK WR840N v6 up to 0.9.1 4.16 - Improper AuthenticationCVE-2024-57050Identify critical remote vulnerabilitiesCriticalSource
TP-Link Archer AX21 (AX1800) - Unauthenticated Command InjectionCVE-2023-1389Identify critical remote vulnerabilitiesHighSource
TP-Link Archer C20 - Authentication BypassCVE-2024-57049Identify critical remote vulnerabilitiesCriticalSource
TP-Link Wireless N Router WR940N - Default LoginIdentify default logins in web-based control panelsHighSource
TRENDnet TEW-827DRU Login Panel - DetectIdentify web-based control panelsInfoSource
TRUfusion Enterprise <= 7.10.4.0 - Admin Contact PortalCVE-2025-27225Identify critical remote vulnerabilitiesHighSource
TRUfusion Enterprise <= 7.10.4.0 - Authentication BypassCVE-2025-27223Identify critical remote vulnerabilitiesCriticalSource
TRUfusion Enterprise <= 7.10.4.0 - Path TraversalCVE-2025-27222Identify critical remote vulnerabilitiesCriticalSource
TVT NVMS 1000 - Local File InclusionCVE-2019-20085Identify critical remote vulnerabilitiesHighSource
Tabby Panel - DetectIdentify web-based control panelsInfoSource
Tableau Services Manager Login Panel - DetectIdentify web-based control panelsInfoSource
Tactical RMM Login Panel - DetectIdentify web-based control panelsInfoSource
Tailon Panel - DetectIdentify web-based control panelsUnknownSource
TamronOS IPTV/VOD - Remote Command ExecutionIdentify critical remote vulnerabilitiesCriticalSource
Tautulli Panel - DetectIdentify web-based control panelsInfoSource
Tautulli Panel - Unauthenticated AccessIdentify web-based control panelsMediumSource
TeamCity < 2023.11.4 - Authentication BypassCVE-2024-27198Identify critical remote vulnerabilitiesCriticalSource
TeamCity Login Panel - DetectIdentify web-based control panelsInfoSource
TeamForge Panel - DetectionIdentify web-based control panelsInfoSource
TeamPass 2.1.27.36 - Improper AuthenticationCVE-2020-12478Identify critical remote vulnerabilitiesHighSource
TeamPass Panel - DetectIdentify web-based control panelsInfoSource
TecConnect OpenMessaging Webservice DetectionIdentify web-based control panelsInfoSource
Tekton Dashboard Panel - DetectIdentify web-based control panelsInfoSource
Telecontrol Server Basic Panel - DetectIdentify web-based control panelsInfoSource
Teleport - Authentication BypassCVE-2025-49825Identify critical remote vulnerabilitiesCriticalSource
Teleport Login Panel - DetectIdentify web-based control panelsInfoSource
Telerik Report Server Login Panel - DetectIdentify web-based control panelsInfoSource
Telesquare TLR-2005KSH - Remote Command ExecutionCVE-2024-29269Identify critical remote vulnerabilitiesHighSource
Telesquare TLR-2005KSH Login Panel - DetectIdentify web-based control panelsInfoSource
TemboSocial Admin Panel - DetectIdentify web-based control panelsInfoSource
Temenos Transact Login Panel - DetectIdentify web-based control panelsInfoSource
Tenable Nessus Panel - DetectIdentify web-based control panelsInfoSource
Tenda 11N - Authentication BypassCVE-2022-42233Identify critical remote vulnerabilitiesCriticalSource
Tenda 11n Wireless Router - Admin PanelIdentify web-based control panelsInfoSource
Tenda Web Master Login Panel - DetectIdentify web-based control panelsInfoSource
Tenemos T24 Login Panel - DetectIdentify web-based control panelsInfoSource
Teradek Cube Administrative Console - PanelIdentify web-based control panelsInfoSource
TerraMaster TOS < 4.2.30 Server Information DisclosureCVE-2022-24990Identify critical remote vulnerabilitiesHighSource
Terraform Enterprise Panel - DetectIdentify web-based control panelsInfoSource
The Events Calendar < 6.4.0.1 - Cross-site ScriptingCVE-2024-4180Identify critical remote vulnerabilitiesMediumSource
The Events Calendar <= 6.15.2 - Information DisclosureIdentify critical remote vulnerabilitiesMediumSource
The Plus Addons for Elementor Page Builder < 4.1.7 - Authentication BypassCVE-2021-24175Identify critical remote vulnerabilitiesCriticalSource
ThemeGrill Demo Importer < 1.6.2 - Database ResetCVE-2020-36333Identify critical remote vulnerabilitiesCriticalSource
Themes Coder Ecommerce <= 1.3.4 - SQL InjectionCVE-2024-13726Identify critical remote vulnerabilitiesHighSource
ThinVNC - Authentication BypassCVE-2022-25226Identify critical remote vulnerabilitiesCriticalSource
Thinfinity VirtualUI Panel - DetectIdentify web-based control panelsInfoSource
Thinfinity VirtualUI User EnumerationCVE-2021-44848Identify critical remote vulnerabilitiesMediumSource
ThingsBoard Panel - DetectIdentify web-based control panelsInfoSource
ThinkPHP 5.0.24 - Information DisclosureCVE-2022-25481Identify critical remote vulnerabilitiesHighSource
ThinkPHP < 3.2.4 - Remote Code ExecutionIdentify critical remote vulnerabilitiesHighSource
Thruk Login Panel - DetectIdentify web-based control panelsInfoSource
Tigase XMPP Server - ExposureIdentify web-based control panelsInfoSource
Tiki Wiki CMS GroupWare - Authentication BypassCVE-2020-15906Identify critical remote vulnerabilitiesCriticalSource
Tiki Wiki CMS Groupware Login Panel - DetectIdentify web-based control panelsInfoSource
TileServer API - Cross Site ScriptingCVE-2024-35627Identify critical remote vulnerabilitiesMediumSource
Time Clock <= 1.2.2 & Time Clock Pro <= 1.1.4 - Remote Code ExecutionCVE-2024-9593Identify critical remote vulnerabilitiesHighSource
TimeKeeper - Default LoginIdentify default logins in web-based control panelsHighSource
Tiny File Manager - Default LoginIdentify default logins in web-based control panelsHighSource
Tiny File Manager Panel - DetectIdentify web-based control panelsInfoSource
Tiny RSS Panel - DetectIdentify web-based control panelsInfoSource
Tixeo Login Panel - DetectIdentify web-based control panelsInfoSource
Tomcat Exposed - DetectIdentify web-based control panelsInfoSource
Tongda OA 11.7 - Authentication BypassIdentify critical remote vulnerabilitiesHighSource
ToolJet - Default LoginIdentify default logins in web-based control panelsHighSource
ToolJet Login Panel - DetectIdentify web-based control panelsInfoSource
Tools4Ever Self-Service Reset Password Manager - PanelIdentify web-based control panelsInfoSource
Topsec TopAppLB - Authentication BypassIdentify critical remote vulnerabilitiesHighSource
Toshiba TopAccess - Default LoginIdentify default logins in web-based control panelsHighSource
Toshiba TopAccess Panel - DetectIdentify web-based control panelsInfoSource
Total Donations Plugin for WordPress < 2.0.6 - Arbitrary Options UpdateCVE-2019-6703Identify critical remote vulnerabilitiesCriticalSource
Totemomail Login Panel - DetectIdentify web-based control panelsInfoSource
Traccar Panel - DetectIdentify web-based control panelsInfoSource
Traccar(Windows) 6.1- 6.8.1 - Local File InclusionCVE-2025-61666Identify critical remote vulnerabilitiesHighSource
Traefik Dashboard Panel - DetectIdentify web-based control panelsInfoSource
Traggo Server - Local File InclusionCVE-2023-34843Identify critical remote vulnerabilitiesHighSource
Trassir WebView - Default LoginIdentify default logins in web-based control panelsHighSource
Trend Micro Apex One Login Panel - DetectIdentify web-based control panelsInfoSource
Trinity Audio <= 5.21.0 - Information ExposureCVE-2025-9196Identify critical remote vulnerabilitiesMediumSource
Triofox - Improper Access ControlCVE-2025-12480Identify critical remote vulnerabilitiesCriticalSource
TrueNAS Panel - DetectIdentify web-based control panelsInfoSource
Tufin SecureTrack Login Panel - DetectIdentify web-based control panelsInfoSource
TurboMeeting - Boolean-based SQL InjectionCVE-2024-38289Identify critical remote vulnerabilitiesCriticalSource
TurnKey LAMP Panel - DetectIdentify web-based control panelsInfoSource
TurnKey OpenVPN Panel - DetectIdentify web-based control panelsInfoSource
Tutor LMS <= 2.7.6 - SQL InjectionCVE-2024-10400Identify critical remote vulnerabilitiesHighSource
UFIDA NC - Arbitrary File ReadIdentify critical remote vulnerabilitiesHighSource
UFIDA U8 CRM cfillbacksetting.php - SQL InjectionIdentify critical remote vulnerabilitiesHighSource
UFIDA U8 CRM fillbacksetting.php - SQL InjectionIdentify critical remote vulnerabilitiesHighSource
UNA CMS <= 14.0.0-RC4 - PHP Object InjectionCVE-2025-32101Identify critical remote vulnerabilitiesCriticalSource
UPS Adapter CS141 SNMP Module Default CredentialsIdentify default logins in web-based control panelsMediumSource
Ubigeo de Peru < 3.6.4 - SQL InjectionCVE-2022-0814Identify critical remote vulnerabilitiesCriticalSource
UiPath Orchestrator Login Panel - DetectIdentify web-based control panelsInfoSource
Umami Panel - DetectIdentify web-based control panelsInfoSource
Umbraco Login Panel - DetectIdentify web-based control panelsInfoSource
UnRaid <=6.80 - Remote Code ExecutionCVE-2020-5847Identify critical remote vulnerabilitiesCriticalSource
Unauthenticated Remote Code Execution – Bricks <= 1.9.6Identify critical remote vulnerabilitiesCriticalSource
UniFi - NFC CredentialsIdentify critical remote vulnerabilitiesHighSource
UniFi Network Login Panel - DetectIdentify web-based control panelsInfoSource
UniFi OS - PanelIdentify web-based control panelsInfoSource
Unibox Panel - DetectIdentify web-based control panelsInfoSource
Unity Plastic SCM Login Panel - DetectIdentify web-based control panelsInfoSource
Universal Media Server v13.2.1 - Cross Site ScriptingIdentify critical remote vulnerabilitiesMediumSource
Unleash Panel - DetectIdentify web-based control panelsInfoSource
Unraid Authentication Bypass VulnerabilityCVE-2020-5849Identify critical remote vulnerabilitiesHighSource
Untangle Administrator Login Panel - DetectIdentify web-based control panelsInfoSource
Uptime Kuma - PanelIdentify web-based control panelsInfoSource
UrBackup Panel - DetectIdentify web-based control panelsInfoSource
User Control Panel - DetectIdentify web-based control panelsInfoSource
User Management/Registration & Login v3.0 - SQL InjectionIdentify critical remote vulnerabilitiesHighSource
User Meta WP Plugin < 3.1 - Sensitive Information ExposureCVE-2024-33575Identify critical remote vulnerabilitiesMediumSource
UserPro <= 5.1.1 - Authentication BypassCVE-2023-2437Identify critical remote vulnerabilitiesCriticalSource
Usermin 2.100 - Username EnumerationCVE-2024-44762Identify critical remote vulnerabilitiesMediumSource
Usermin Panel - DetectIdentify web-based control panelsInfoSource
V2924 Admin Login Panel - DetectIdentify web-based control panelsInfoSource
VICIdial - SQL InjectionCVE-2024-8503Identify critical remote vulnerabilitiesCriticalSource
VMware Aria Operations Login - DetectIdentify web-based control panelsInfoSource
VMware Carbon Black EDR Panel - DetectIdentify web-based control panelsInfoSource
VMware Cloud Director Availability Login Panel - DetectIdentify web-based control panelsInfoSource
VMware Cloud Director Login Panel - DetectIdentify web-based control panelsInfoSource
VMware FTP Server Login Panel - DetectIdentify web-based control panelsInfoSource
VMware HCX Login Panel - DetectIdentify web-based control panelsInfoSource
VMware NSX Login Panel - DetectIdentify web-based control panelsInfoSource
VMware NSX SD-WAN Edge - Command InjectionCVE-2018-6961Identify critical remote vulnerabilitiesCriticalSource
VMware Workspace ONE Access - Server-Side Template InjectionCVE-2022-22954Identify critical remote vulnerabilitiesCriticalSource
VMware Workspace ONE UEM Airwatch Login Panel - DetectIdentify web-based control panelsInfoSource
VMware Workspace ONE UEM Airwatch Self-Service Portal - DetectIdentify web-based control panelsInfoSource
VMware vCenter Converter Panel - DetectIdentify web-based control panelsInfoSource
VMware vCenter Server - Out-of-Bounds WriteCVE-2023-34048Identify critical remote vulnerabilitiesCriticalSource
VMware vCloud Director Panel - DetectIdentify web-based control panelsInfoSource
VMware vRealize Log Insight - Improper Access Control to RCECVE-2022-31704Identify critical remote vulnerabilitiesCriticalSource
VMware vRealize Log Insight - Path TraversalCVE-2022-31706Identify critical remote vulnerabilitiesCriticalSource
VMware vRealize Log Insight < v8.10.2 - Information DisclosureCVE-2022-31711Identify critical remote vulnerabilitiesMediumSource
Vanna - SQL injectionCVE-2024-5827Identify critical remote vulnerabilitiesCriticalSource
Vault Login Panel - DetectIdentify web-based control panelsInfoSource
Vaultwarden Login Panel - DetectIdentify web-based control panelsInfoSource
VectorAdmin Panel - DetectIdentify web-based control panelsInfoSource
Veeam Backup & Replication - UnauthenticatedCVE-2024-40711Identify critical remote vulnerabilitiesCriticalSource
Veeam Backup Enterprise Manager Login - DetectIdentify web-based control panelsInfoSource
Veeam Backup for Google Cloud Platform Panel - DetectIdentify web-based control panelsInfoSource
Veeam Backup for Microsoft Azure Panel - DetectIdentify web-based control panelsInfoSource
Veeam Login Panel - DetectIdentify web-based control panelsInfoSource
Veracore Login - DetectIdentify web-based control panelsInfoSource
Veritas NetBackup OpsCenter Analytics Login - DetectIdentify web-based control panelsInfoSource
Veriz0wn OSINT - DetectIdentify web-based control panelsInfoSource
Verizon Router Panel - DetectIdentify web-based control panelsInfoSource
Versa Concerto API Path Based - Authentication BypassIdentify critical remote vulnerabilitiesCriticalSource
Versa Concerto Actuator Endpoint - Authentication BypassIdentify critical remote vulnerabilitiesCriticalSource
Versa Director Login Panel - DetectIdentify web-based control panelsInfoSource
Versa FlexVNF - Default LoginIdentify default logins in web-based control panelsHighSource
Versa FlexVNF Panel - DetectIdentify web-based control panelsInfoSource
VertaAI ModelDB - Path TraversalCVE-2023-6023Identify critical remote vulnerabilitiesHighSource
Vertex Tax Installer Panel - DetectIdentify web-based control panelsInfoSource
VictoriaMetrics Panel - DetectIdentify web-based control panelsInfoSource
Vidyo Admin Login Panel - DetectIdentify web-based control panelsInfoSource
Viessmann Vitogate 300 - Hardcoded PasswordCVE-2023-5222Identify critical remote vulnerabilitiesMediumSource
Viessmann Vitogate 300 - Remote Code ExecutionCVE-2023-45852Identify critical remote vulnerabilitiesCriticalSource
Vinchin Backup & Recovery Panel - DetectIdentify web-based control panelsInfoSource
Virtua Software Cobranca <12R - Blind SQL InjectionCVE-2021-37589Identify critical remote vulnerabilitiesHighSource
Virtua Software Panel - DetectIdentify web-based control panelsInfoSource
Vite - Arbitrary File ReadCVE-2025-30208Identify critical remote vulnerabilitiesMediumSource
Vite - Information DisclosureIdentify critical remote vulnerabilitiesMediumSource
Vite Dev Server - Path TraversalCVE-2025-58751Identify critical remote vulnerabilitiesLowSource
Vite Development Server - Path TraversalCVE-2025-31125Identify critical remote vulnerabilitiesMediumSource
Vite server.fs.deny Bypass - Local File InclusionCVE-2025-31486Identify critical remote vulnerabilitiesMediumSource
VoIPmonitor Login Panel - DetectIdentify web-based control panelsInfoSource
Vodafone Vox UI Login Panel - DetectIdentify web-based control panelsInfoSource
Void Aural Rec Monitor 9.0.0.1 - SQL InjectionCVE-2021-25899Identify critical remote vulnerabilitiesHighSource
VoipMonitor - Pre-Auth SQL InjectionCVE-2022-24260Identify critical remote vulnerabilitiesCriticalSource
VoipMonitor <24.61 - Remote Code ExecutionCVE-2021-30461Identify critical remote vulnerabilitiesCriticalSource
Vtiger CRM - Default LoginIdentify default logins in web-based control panelsHighSource
Vtiger CRM v7.2.0 - Directory ListingCVE-2020-19363Identify critical remote vulnerabilitiesMediumSource
Vue PACS - PanelIdentify web-based control panelsInfoSource
Vue Vben Admin - Default CredentialsCVE-2025-25570Identify critical remote vulnerabilitiesCriticalSource
WAGO - Remote Command ExecutionCVE-2023-1698Identify critical remote vulnerabilitiesCriticalSource
WAGO Web-based Management - Default LoginIdentify default logins in web-based control panelsHighSource
WAVLINK - Access ControlCVE-2020-10973Identify critical remote vulnerabilitiesHighSource
WAVLINK AC1200 - Information DisclosureCVE-2021-44260Identify critical remote vulnerabilitiesHighSource
WAVLINK Quantum D4G (WL-WN531G3) - Information DisclosureCVE-2022-44356Identify critical remote vulnerabilitiesHighSource
WAVLINK WN530H4 M30H4.V5030.190403 - Information DisclosureCVE-2020-12127Identify critical remote vulnerabilitiesHighSource
WAVLINK WN530H4 live_api.cgi - Command InjectionCVE-2020-12124Identify critical remote vulnerabilitiesCriticalSource
WAVLINK WN530HG4 - Improper Access ControlCVE-2022-34049Identify critical remote vulnerabilitiesMediumSource
WAVLINK WN530HG4 - Improper Access ControlCVE-2022-34047Identify critical remote vulnerabilitiesHighSource
WAVLINK WN530HG4 - Improper Access ControlCVE-2022-34045Identify critical remote vulnerabilitiesCriticalSource
WAVLINK WN533A8 - Improper Access ControlCVE-2022-34046Identify critical remote vulnerabilitiesHighSource
WAVLINK WN535 G3 - Improper Access ControlCVE-2022-34576Identify critical remote vulnerabilitiesHighSource
WAVLINK WN535 G3 - Information DisclosureCVE-2022-31845Identify critical remote vulnerabilitiesHighSource
WAVLINK WN535 G3 - Information DisclosureCVE-2022-31846Identify critical remote vulnerabilitiesHighSource
WAVLINK WN579 X3 M79X3.V5030.180719 - Information DisclosureCVE-2022-31847Identify critical remote vulnerabilitiesHighSource
WCFM Membership <= 2.10.0 - Broken Access ControlCVE-2022-4940Identify critical remote vulnerabilitiesHighSource
WCFM WooCommerce Multivendor Marketplace < 3.4.12 - SQL InjectionCVE-2021-24849Identify critical remote vulnerabilitiesCriticalSource
WD My Cloud Panel - DetectIdentify web-based control panelsInfoSource
WP Fastest Cache 1.2.2 - SQL InjectionCVE-2023-6063Identify critical remote vulnerabilitiesHighSource
WP Google Maps < 9.0.48 - Cross-Site ScriptingCVE-2025-11307Identify critical remote vulnerabilitiesHighSource
WP Hotel Booking < 1.10.4 - PHP Object InjectionCVE-2020-29047Identify critical remote vulnerabilitiesCriticalSource
WP Popup Builder Popup Forms and Marketing Lead Generation <= 1.3.5 - Arbitrary Shortcode ExecutionCVE-2024-9061Identify critical remote vulnerabilitiesHighSource
WP Query Console <= 1.0 - Remote Code ExecutionCVE-2024-50498Identify critical remote vulnerabilitiesCriticalSource
WP Umbrella Update Backup Restore & Monitoring <= 2.17.0 - Local File InclusionCVE-2024-12209Identify critical remote vulnerabilitiesCriticalSource
WP User <= 7.0 - Unauthenticated SQLiCVE-2022-4049Identify critical remote vulnerabilitiesCriticalSource
WP Visitor Statistics (Real Time Traffic) < 6.9 - SQL InjectionCVE-2023-0600Identify critical remote vulnerabilitiesCriticalSource
WP-Recall – Plugin <= 16.26.10 - Unauthenticated SQL InjectionCVE-2025-1323Identify critical remote vulnerabilitiesHighSource
WPEngine WPGraphQL 0.2.3 - Unauthenticated Comment PostingCVE-2019-9881Identify critical remote vulnerabilitiesMediumSource
WPEngine WPGraphQL 0.2.3 - Unauthenticated User Information DisclosureCVE-2019-9880Identify critical remote vulnerabilitiesCriticalSource
WPMobile.App <= 11.56 - Open RedirectCVE-2024-13888Identify critical remote vulnerabilitiesHighSource
WPS Hide Login <= 1.5.2.2 - Login Page BypassIdentify critical remote vulnerabilitiesHighSource
WPS Hide Login <= 1.9.15.2 - Login Page DisclosureCVE-2024-2473Identify critical remote vulnerabilitiesMediumSource
WS-FTP Ad Hoc Transfer Panel - DetectIdentify web-based control panelsInfoSource
WSO2 Management Console - Authentication BypassCVE-2025-5605Identify critical remote vulnerabilitiesMediumSource
WSO2 Management Console - Default LoginIdentify default logins in web-based control panelsHighSource
WSO2 Management Console Login Panel - DetectIdentify web-based control panelsInfoSource
WS_FTP Server - Insecure DeserializationCVE-2023-40044Identify critical remote vulnerabilitiesCriticalSource
WS_FTP Server Web Transfer - Panel DetectIdentify web-based control panelsInfoSource
WWBN AVideo 11.6 - Cross-Site ScriptingCVE-2023-48728Identify critical remote vulnerabilitiesCriticalSource
Wagtail Login - DetectIdentify web-based control panelsInfoSource
Wallix Access Manager Panel - DetectIdentify web-based control panelsInfoSource
WampServer Panel - DetectIdentify web-based control panelsInfoSource
Watcher Panel - DetectIdentify web-based control panelsInfoSource
Watershed Login Panel - DetectIdentify web-based control panelsInfoSource
Wavlink - Improper Access ControlCVE-2022-48165Identify critical remote vulnerabilitiesHighSource
Wavlink WL-WN530HG4 M30HG4.V5030.201217 - Information DisclosureCVE-2022-48166Identify critical remote vulnerabilitiesHighSource
Wavlink WL-WN533A8 M33A8.V5030.190716 - Information DisclosureCVE-2022-48164Identify critical remote vulnerabilitiesHighSource
Wavlink WN535K2/WN535K3 - OS Command InjectionCVE-2022-2487Identify critical remote vulnerabilitiesHighSource
Wazuh - Default LoginIdentify default logins in web-based control panelsHighSource
Wazuh Login PanelIdentify web-based control panelsInfoSource
WeChat agentinfo - Information ExposureIdentify critical remote vulnerabilitiesHighSource
WeGIA - Directory TraversalCVE-2025-55169Identify critical remote vulnerabilitiesCriticalSource
Web File Manager Login Panel - DetectIdentify web-based control panelsInfoSource
Web Transfer Client Login Panel - DetectIdentify web-based control panelsInfoSource
Web Viewer for Samsung DVR - DetectIdentify web-based control panelsInfoSource
WebIQ 2.15.9 - Directory TraversalCVE-2024-8752Identify critical remote vulnerabilitiesHighSource
WebMethod Integration Server - Default LoginIdentify default logins in web-based control panelsHighSource
WebPageTest Login Panel - DetectIdentify web-based control panelsInfoSource
WebShell4 Login Panel - DetectIdentify web-based control panelsInfoSource
WebTitan Cloud Panel - DetectIdentify web-based control panelsInfoSource
WebcomCo - PanelIdentify web-based control panelsInfoSource
Webmin - Default LoginIdentify default logins in web-based control panelsHighSource
Webmin < 1.290 / Usermin < 1.220 - Arbitrary File DisclosureCVE-2006-3392Identify critical remote vulnerabilitiesMediumSource
Webmin < 1.920 - Authenticated Remote Code ExecutionCVE-2019-15642Identify critical remote vulnerabilitiesHighSource
Webmin <= 1.920 - Unauthenticated Remote Command ExecutionCVE-2019-15107Identify critical remote vulnerabilitiesCriticalSource
Webmin Admin Login Panel - DetectIdentify web-based control panelsInfoSource
Webmodule Login Panel - DetectIdentify web-based control panelsInfoSource
Webroot Login Panel - DetectIdentify web-based control panelsInfoSource
Webuzo Admin Login Panel - DetectIdentify web-based control panelsInfoSource
WeiPHP 5.0 - SQL InjectionCVE-2020-20300Identify critical remote vulnerabilitiesCriticalSource
Weiphp Panel - DetectIdentify web-based control panelsInfoSource
Western Digital MyCloud NAS - Authentication BypassCVE-2018-17153Identify critical remote vulnerabilitiesCriticalSource
Whatsup Gold Login Panel - DetectIdentify web-based control panelsInfoSource
Wifisky - Default LoginIdentify default logins in web-based control panelsHighSource
Wildfly - Default LoginIdentify default logins in web-based control panelsHighSource
Wildix Collaboration Panel - DetectIdentify web-based control panelsInfoSource
Windows Admin Center Panel - DetectionIdentify web-based control panelsInfoSource
Wing FTP Server <= 7.4.3 - Path Disclosure via Overlong UID CookieCVE-2025-47813Identify critical remote vulnerabilitiesMediumSource
Wing FTP Server <= 7.4.3 - Remote Code ExecutionCVE-2025-47812Identify critical remote vulnerabilitiesCriticalSource
Wiren Board WebUI Panel - DetectIdentify web-based control panelsMediumSource
Woodpecker CI Panel - DetectIdentify web-based control panelsInfoSource
Woodwing Studio Server Panel - DetectIdentify web-based control panelsInfoSource
WordPress 12 Step Meeting List Plugin <= 3.14.33 - Cross-Site ScriptingCVE-2024-35693Identify critical remote vulnerabilitiesMediumSource
WordPress <= 5.2.4 - Unauthenticated View Private/Draft PostsCVE-2019-17671Identify critical remote vulnerabilitiesMediumSource
WordPress AI Engine Plugin - Token ExposureCVE-2025-11749Identify critical remote vulnerabilitiesCriticalSource
WordPress AMP - Full Path DisclosureIdentify critical remote vulnerabilitiesLowSource
WordPress AddToAny Share Buttons Plugin - Full Path DisclosureIdentify critical remote vulnerabilitiesLowSource
WordPress Astra - Full Path DisclosureIdentify critical remote vulnerabilitiesLowSource
WordPress Astra Sites - Full Path DisclosureIdentify critical remote vulnerabilitiesLowSource
WordPress BackWPup < 4.0.4 - Backup File DisclosureCVE-2023-7164Identify critical remote vulnerabilitiesHighSource
WordPress Backup Migration <= 1.3.6 - Path TraversalCVE-2023-6266Identify critical remote vulnerabilitiesHighSource
WordPress CMB2 - Full Path DisclosureIdentify critical remote vulnerabilitiesLowSource
WordPress Coming Soon Page - Full Path DisclosureIdentify critical remote vulnerabilitiesLowSource
WordPress Core - Post Author Email DisclosureCVE-2023-5561Identify critical remote vulnerabilitiesMediumSource
WordPress Download Manager - File Password ExposureCVE-2023-6421Identify critical remote vulnerabilitiesHighSource
WordPress Download Manager < 3.3.07 - Unauthenticated Data ExposureCVE-2024-13126Identify critical remote vulnerabilitiesMediumSource
WordPress Duplicator 1.3.24 & 1.3.26 - Local File InclusionCVE-2020-11738Identify critical remote vulnerabilitiesHighSource
WordPress Eventin (Themewinter) ≤ 4.0.26 - Arbitrary File DownloadCVE-2025-47445Identify critical remote vulnerabilitiesHighSource
WordPress File Upload <= 4.24.11 - Arbitrary File ReadCVE-2024-9047Identify critical remote vulnerabilitiesCriticalSource
WordPress Gift Voucher <4.1.8 - Blind SQL InjectionCVE-2018-16159Identify critical remote vulnerabilitiesCriticalSource
WordPress Grow by Tradedoubler Plugin < 2.0.22 - Unauthenticated Local File InclusionCVE-2024-6460Identify critical remote vulnerabilitiesCriticalSource
WordPress HTML5 Video Player - SQL InjectionCVE-2024-1061Identify critical remote vulnerabilitiesHighSource
WordPress Job Portal < 2.0.6 - SQL InjectionCVE-2023-4490Identify critical remote vulnerabilitiesCriticalSource
WordPress ManageWP Worker - Full Path DisclosureIdentify critical remote vulnerabilitiesLowSource
WordPress Members / Membership & User Role Editor Plugin - Error Log DisclosureIdentify critical remote vulnerabilitiesLowSource
WordPress Members Plugin - Debug/Error Log DisclosureIdentify critical remote vulnerabilitiesLowSource
WordPress My Calendar <3.4.22 - SQL InjectionCVE-2023-6360Identify critical remote vulnerabilitiesHighSource
WordPress Newsletter - Log File ExposureIdentify critical remote vulnerabilitiesMediumSource
WordPress NextGEN Gallery Pro - Error Log DisclosureIdentify critical remote vulnerabilitiesMediumSource
WordPress OceanWP - Full Path DisclosureIdentify critical remote vulnerabilitiesLowSource
WordPress PHPMailer < 5.2.18 - Remote Code ExecutionCVE-2016-10033Identify critical remote vulnerabilitiesCriticalSource
WordPress Paid Memberships Pro <2.6.7 - Blind SQL InjectionCVE-2021-25114Identify critical remote vulnerabilitiesCriticalSource
WordPress Paid Memberships Pro <2.9.8 - Blind SQL InjectionCVE-2023-23488Identify critical remote vulnerabilitiesCriticalSource
WordPress Passive Detection - Plugins & ThemesIdentify web-based control panelsInfoSource
WordPress Plugin GDPR Cookie Consent - Full Path DisclosureIdentify critical remote vulnerabilitiesLowSource
WordPress Plugin Google Tag Manager - Full Path DisclosureIdentify critical remote vulnerabilitiesLowSource
WordPress Plugin Imsanity - Full Path DisclosureIdentify critical remote vulnerabilitiesLowSource
WordPress Plugin InfiniteWP Client - Full Path DisclosureIdentify critical remote vulnerabilitiesLowSource
WordPress Plugin Max Mega Menu (megamenu) - Full Path DisclosureIdentify critical remote vulnerabilitiesLowSource
WordPress Plugin Newsletter - Full Path DisclosureIdentify critical remote vulnerabilitiesLowSource
WordPress Plugin SG Optimizer - Full Path DisclosureIdentify critical remote vulnerabilitiesLowSource
WordPress Plugin SSL Insecure Content Fixer - Full Path DisclosureIdentify critical remote vulnerabilitiesLowSource
WordPress Plugin Safe SVG - Full Path DisclosureIdentify critical remote vulnerabilitiesLowSource
WordPress Plugin Table of Contents Plus - Full Path DisclosureIdentify critical remote vulnerabilitiesLowSource
WordPress Plugin WP Statistics <= 13.1.5 - SQL InjectionCVE-2022-0651Identify critical remote vulnerabilitiesCriticalSource
WordPress Plugin WP Statistics <= 13.1.5 - SQL InjectionCVE-2022-25148Identify critical remote vulnerabilitiesCriticalSource
WordPress Plugin WP Statistics <= 13.1.5 - SQL InjectionCVE-2022-25149Identify critical remote vulnerabilitiesCriticalSource
WordPress Plugin WooCommerce Admin (woocommerce-admin) Full Path DisclosureIdentify critical remote vulnerabilitiesLowSource
WordPress Plugin iThemes Security - Full Path DisclosureIdentify critical remote vulnerabilitiesLowSource
WordPress Plugin reCaptcha by BestWebSoft (google-captcha) - Full Path DisclosureIdentify critical remote vulnerabilitiesLowSource
WordPress Pretty Links - Full Path DisclosureIdentify critical remote vulnerabilitiesLowSource
WordPress SEO Plugin Rank Math - Full Path DisclosureIdentify critical remote vulnerabilitiesLowSource
WordPress SVG Support - Full Path DisclosureIdentify critical remote vulnerabilitiesLowSource
WordPress Simple Job Board - Unauthorized Data AccessCVE-2024-0593Identify critical remote vulnerabilitiesMediumSource
WordPress Statistics <13.0.8 - Blind SQL InjectionCVE-2021-24340Identify critical remote vulnerabilitiesHighSource
WordPress Storefront Theme - Full Path DisclosureIdentify critical remote vulnerabilitiesLowSource
WordPress Table of Contents Plus - Full Path DisclosureIdentify critical remote vulnerabilitiesLowSource
WordPress The Events Calendar - Full Path DisclosureIdentify critical remote vulnerabilitiesLowSource
WordPress Tourfic Plugin <= 2.11.7 - Cross-Site ScriptingCVE-2024-29137Identify critical remote vulnerabilitiesHighSource
WordPress Ultimate Member 2.1.3 - 2.8.2 – SQL InjectionCVE-2024-1071Identify critical remote vulnerabilitiesCriticalSource
WordPress UpdraftPlus - Full Path DisclosureIdentify critical remote vulnerabilitiesLowSource
WordPress Visitor Statistics <=5.7 - SQL InjectionCVE-2022-33965Identify critical remote vulnerabilitiesCriticalSource
WordPress W3 Total Cache - Cache Files ExposureIdentify critical remote vulnerabilitiesHighSource
WordPress WP Mail SMTP - Full Path DisclosureIdentify critical remote vulnerabilitiesLowSource
WordPress WP Maintenance Mode - Full Path DisclosureIdentify critical remote vulnerabilitiesLowSource
WordPress WP Migrate DB - Full Path DisclosureIdentify critical remote vulnerabilitiesLowSource
WordPress WP-Advanced-Search <= 3.3.9 - SQL InjectionCVE-2024-9796Identify critical remote vulnerabilitiesCriticalSource
WordPress WP-PageNavi - Full Path DisclosureIdentify critical remote vulnerabilitiesLowSource
WordPress WPForms - Full Path DisclosureIdentify critical remote vulnerabilitiesLowSource
WordPress Wordfence - Configuration File DisclosureIdentify critical remote vulnerabilitiesMediumSource
WordPress Wordfence - Rules File DisclosureIdentify critical remote vulnerabilitiesMediumSource
WordPress Wordfence - WAF Logs and Data DisclosureIdentify critical remote vulnerabilitiesLowSource
WordPress YITH WooCommerce Wishlist - Full Path DisclosureIdentify critical remote vulnerabilitiesLowSource
WordPress Yoast SEO - Full Path DisclosureIdentify critical remote vulnerabilitiesLowSource
Wordpress Gift Cards <= 4.3.1 - SQL InjectionCVE-2023-28662Identify critical remote vulnerabilitiesCriticalSource
Wordpress Polls Widget < 1.5.3 - SQL InjectionCVE-2021-24442Identify critical remote vulnerabilitiesCriticalSource
Wordpress WPMobile.App >= 11.42 - Cross-Site ScriptingCVE-2024-35694Identify critical remote vulnerabilitiesHighSource
Worpress Backup Migration <= 1.3.7 - Unauthenticated Remote Code ExecutionCVE-2023-6553Identify critical remote vulnerabilitiesCriticalSource
Wowza Streaming Engine Manager Panel - DetectIdentify web-based control panelsInfoSource
WpStickyBar <= 2.1.0 - SQL InjectionCVE-2024-5765Identify critical remote vulnerabilitiesCriticalSource
X-UI - Default LoginIdentify default logins in web-based control panelsHighSource
XAMPP PHP info Page - DetectIdentify critical remote vulnerabilitiesLowSource
XDS-AMR Status Login Panel - DetectIdentify web-based control panelsInfoSource
XNAT - Default LoginIdentify default logins in web-based control panelsHighSource
XNAT Login Panel - DetectIdentify web-based control panelsInfoSource
XSpeeder Login - DetectIdentify web-based control panelsInfoSource
XVR Login Panel - DetectIdentify web-based control panelsInfoSource
XWiki - Cross-Site ScriptingCVE-2023-35155Identify critical remote vulnerabilitiesHighSource
XWiki - Cross-Site ScriptingCVE-2023-35158Identify critical remote vulnerabilitiesCriticalSource
XWiki - HQL InjectionCVE-2025-52472Identify critical remote vulnerabilitiesHighSource
XWiki - Information DisclosureCVE-2025-55749Identify critical remote vulnerabilitiesHighSource
XWiki < 12.10.11, 13.4.4 & 13.9-rc-1 - Information DisclosureCVE-2022-24819Identify critical remote vulnerabilitiesMediumSource
XWiki < 14.10.14 - Cross-Site ScriptingCVE-2023-45136Identify critical remote vulnerabilitiesCriticalSource
XWiki < 14.10.14 - Cross-Site ScriptingCVE-2023-46732Identify critical remote vulnerabilitiesCriticalSource
XWiki < 14.10.5 - Cross-Site ScriptingCVE-2023-35162Identify critical remote vulnerabilitiesCriticalSource
XWiki < 4.10.15 - Email DisclosureCVE-2023-50720Identify critical remote vulnerabilitiesMediumSource
XWiki < 4.10.15 - Information DisclosureCVE-2023-48241Identify critical remote vulnerabilitiesHighSource
XWiki < 4.10.15 - Sensitive Information DisclosureCVE-2023-50719Identify critical remote vulnerabilitiesHighSource
XWiki < 4.10.20 - Remote code executionCVE-2024-31982Identify critical remote vulnerabilitiesCriticalSource
XWiki >= 13.10.8 - Cross-Site ScriptingCVE-2023-29506Identify critical remote vulnerabilitiesMediumSource
XWiki >= 2.5-milestone-2 - Cross-Site ScriptingCVE-2023-35160Identify critical remote vulnerabilitiesCriticalSource
XWiki >= 3.4-milestone-1 - Cross-Site ScriptingCVE-2023-35159Identify critical remote vulnerabilitiesCriticalSource
XWiki >= 6.0-rc-1 - Cross-Site ScriptingCVE-2023-35156Identify critical remote vulnerabilitiesCriticalSource
XWiki >= 6.2-milestone-1 - Cross-Site ScriptingCVE-2023-35161Identify critical remote vulnerabilitiesCriticalSource
XWiki Platform - Cross-Site ScriptingCVE-2025-32430Identify critical remote vulnerabilitiesMediumSource
XWiki Platform - Information DisclosureCVE-2025-55747Identify critical remote vulnerabilitiesHighSource
XWiki Platform - Path TraversalCVE-2025-55748Identify critical remote vulnerabilitiesHighSource
XWiki Platform - Remote Code ExecutionCVE-2025-24893Identify critical remote vulnerabilitiesCriticalSource
XWiki Platform - Remote Code ExecutionCVE-2023-37462Identify critical remote vulnerabilitiesCriticalSource
XWiki Platform - SQL InjectionCVE-2025-32429Identify critical remote vulnerabilitiesCriticalSource
XWiki Platform - Unauthorized Document History AccessCVE-2024-45591Identify critical remote vulnerabilitiesMediumSource
XWiki REST API - Attachments DisclosureCVE-2025-46554Identify critical remote vulnerabilitiesHighSource
XWiki REST API - Private Pages DisclosureCVE-2025-29925Identify critical remote vulnerabilitiesHighSource
XWiki REST API Query - SQL InjectionCVE-2025-32969Identify critical remote vulnerabilitiesCriticalSource
XXL-JOB - Default LoginIdentify default logins in web-based control panelsHighSource
XXLJOB Admin Login Panel - DetectIdentify web-based control panelsInfoSource
Xeams Admin Console Login Panel - DetectIdentify web-based control panelsInfoSource
Xfinity Panel - DetectIdentify web-based control panelsInfoSource
Xiaomi Wireless Router Admin Panel - DetectIdentify web-based control panelsInfoSource
Xibo CMS Login Panel - DetectIdentify web-based control panelsInfoSource
XploitSPY - Default LoginIdentify default logins in web-based control panelsHighSource
YARPP <= 5.30.10 - Missing AuthorizationCVE-2024-43919Identify critical remote vulnerabilitiesMediumSource
Yacht - Default LoginIdentify default logins in web-based control panelsHighSource
YeaLink DM 3.6.0.20 - Remote Command InjectionCVE-2021-27561Identify critical remote vulnerabilitiesCriticalSource
Yellow Pencil Visual Theme Customizer < 7.2.1 - Privilege EscalationCVE-2019-11886Identify critical remote vulnerabilitiesHighSource
Yellowfin Information Collaboration - DetectIdentify web-based control panelsInfoSource
YesWiki < 4.5.4 - Cross-Site ScriptingCVE-2025-46550Identify critical remote vulnerabilitiesMediumSource
YesWiki <2022-07-07 - SQL InjectionIdentify critical remote vulnerabilitiesCriticalSource
YesWiki Reflected XSS via File UploadCVE-2025-46349Identify critical remote vulnerabilitiesHighSource
Yeswiki < 4.5.2 - Unauthenticated Path TraversalCVE-2025-31131Identify critical remote vulnerabilitiesHighSource
Yopass Panel - DetectIdentify web-based control panelsInfoSource
Youzify < 1.2.0 - Unauthenticated SQLiCVE-2022-1950Identify critical remote vulnerabilitiesCriticalSource
YunoHost Admin Panel - DetectIdentify web-based control panelsInfoSource
YzmCMS Login Panel - DetectIdentify web-based control panelsInfoSource
Z-BlogPHP Admin Login Panel - DetectIdentify web-based control panelsInfoSource
Z-BlogPHP Panel - DetectIdentify web-based control panelsInfoSource
ZEROF Web Server 2.0 - SQL InjectionCVE-2022-25322Identify critical remote vulnerabilitiesCriticalSource
ZKTeco BioTime <= 9.0.1 - Privilege EscalationCVE-2023-38952Identify critical remote vulnerabilitiesHighSource
ZKTeco BioTime v8.5.5 - Path TraversalCVE-2023-38950Identify critical remote vulnerabilitiesHighSource
ZOHO ManageEngine ADAudit/ADManager Panel - DetectIdentify web-based control panelsInfoSource
ZOHO ManageEngine ADSelfService Plus - DetectIdentify web-based control panelsInfoSource
ZOHO ManageEngine APEX IT Help-Desk Panel - DetectIdentify web-based control panelsInfoSource
ZOHO ManageEngine Analytics Plus Panel - DetectIdentify web-based control panelsInfoSource
ZOHO ManageEngine AssetExplorer Panel - DetectIdentify web-based control panelsInfoSource
ZOHO ManageEngine Desktop Panel - DetectIdentify web-based control panelsInfoSource
ZOHO ManageEngine Exchange Reporter Plus Panel - DetectIdentify web-based control panelsInfoSource
ZOHO ManageEngine OpManager Panel - DetectIdentify web-based control panelsInfoSource
ZOHO ManageEngine ServiceDesk Panel - DetectIdentify web-based control panelsInfoSource
ZOHO ManageEngine SupportCenter Panel - DetectIdentify web-based control panelsInfoSource
ZTE Panel - DetectIdentify web-based control panelsInfoSource
ZTE ZXHN-F660T/F660A - Default CredentialsCVE-2025-53558Identify critical remote vulnerabilitiesHighSource
Zabbix - Default LoginIdentify default logins in web-based control panelsHighSource
Zabbix - SAML SSO Authentication BypassCVE-2022-23131Identify critical remote vulnerabilitiesCriticalSource
Zabbix - SQL InjectionCVE-2016-10134Identify critical remote vulnerabilitiesCriticalSource
Zabbix <=4.4 - Authentication BypassCVE-2019-17382Identify critical remote vulnerabilitiesCriticalSource
Zabbix Login Panel - DetectIdentify web-based control panelsInfoSource
Zabbix Setup Configuration Authentication BypassCVE-2022-23134Identify critical remote vulnerabilitiesLowSource
Zammad Helpdesk Panel - DetectIdentify web-based control panelsInfoSource
Zebra Printer - Default LoginIdentify default logins in web-based control panelsHighSource
ZenML Dashboard Panel - DetectIdentify web-based control panelsInfoSource
ZenML ZenML Server - Improper AuthenticationCVE-2024-25723Identify critical remote vulnerabilitiesCriticalSource
ZeroShell <= 1.0beta11 Remote Code ExecutionCVE-2009-0545Identify critical remote vulnerabilitiesCriticalSource
ZeroShell Panel - DetectIdentify web-based control panelsInfoSource
Zeroshell 3.9.0 - Remote Command ExecutionCVE-2019-12725Identify critical remote vulnerabilitiesCriticalSource
Zeroshell 3.9.3 - Command InjectionCVE-2020-29390Identify critical remote vulnerabilitiesCriticalSource
Zimbra - Cross-Site Scripting via ICS FilesCVE-2025-27915Identify critical remote vulnerabilitiesMediumSource
Zimbra Collaboration (ZCS) - Cross Site ScriptingCVE-2022-27926Identify critical remote vulnerabilitiesMediumSource
Zimbra Collaboration - Cross-Site Scripting (XSS)CVE-2024-27443Identify critical remote vulnerabilitiesMediumSource
Zimbra Collaboration - Local File InclusionCVE-2025-68645Identify critical remote vulnerabilitiesHighSource
Zimbra Collaboration - Unrestricted File UploadCVE-2022-41352Identify critical remote vulnerabilitiesCriticalSource
Zimbra Collaboration Suite - Memcached Command InjectionCVE-2022-27924Identify critical remote vulnerabilitiesHighSource
Zimbra Collaboration Suite - SSRFCVE-2019-9621Identify critical remote vulnerabilitiesHighSource
Zimbra Collaboration Suite 8.8.15/9.0 - Remote Code ExecutionCVE-2022-37042Identify critical remote vulnerabilitiesCriticalSource
Zimbra Collaboration Suite < 8.8.15 - Improper EncodingCVE-2022-24682Identify critical remote vulnerabilitiesMediumSource
Zimbra Collaboration Suite Login Panel - DetectIdentify web-based control panelsInfoSource
Zimbra Panel - DetectIdentify web-based control panelsInfoSource
Zipkin Login Panel - DetectIdentify web-based control panelsInfoSource
Zitadel - User Registration BypassCVE-2024-49757Identify critical remote vulnerabilitiesHighSource
Zoho ManageEngine - Access Control BypassCVE-2022-29081Identify critical remote vulnerabilitiesCriticalSource
Zoho ManageEngine - Internal Hostname DisclosureCVE-2022-23779Identify critical remote vulnerabilitiesMediumSource
Zoho ManageEngine - Remote Code ExecutionCVE-2022-35405Identify critical remote vulnerabilitiesCriticalSource
Zoho ManageEngine Desktop Central - Remote Code ExecutionCVE-2021-44515Identify critical remote vulnerabilitiesCriticalSource
Zoho ManageEngine Network Configuration Manager Panel - DetectIdentify web-based control panelsInfoSource
Zoho ManageEngine OpManager - SQL InjectionCVE-2018-17283Identify critical remote vulnerabilitiesHighSource
Zoho ManageEngine OpManager < 12.5.329 - Remote Code ExecutionCVE-2021-3287Identify critical remote vulnerabilitiesCriticalSource
Zoho ManageEngine ServiceDesk Plus - Authentication BypassCVE-2021-37415Identify critical remote vulnerabilitiesCriticalSource
Zoho ManageEngine ServiceDesk Plus - Remote Code ExecutionCVE-2021-44077Identify critical remote vulnerabilitiesCriticalSource
ZoneMinder - SQL InjectionCVE-2024-43360Identify critical remote vulnerabilitiesCriticalSource
ZoneMinder Login Panel - DetectIdentify web-based control panelsInfoSource
Zoraxy Login Panel - DetectIdentify web-based control panelsInfoSource
Zuul Panel - DetectIdentify web-based control panelsInfoSource
ZyXel Router Login Panel - DetectIdentify web-based control panelsInfoSource
ZyXel USG - Hardcoded CredentialsCVE-2020-29583Identify critical remote vulnerabilitiesCriticalSource
Zyxel - Authentication BypassCVE-2022-0342Identify critical remote vulnerabilitiesCriticalSource
Zyxel Firewall Panel - DetectIdentify web-based control panelsInfoSource
Zyxel NAS Firmware 5.21- Remote Code ExecutionCVE-2020-9054Identify critical remote vulnerabilitiesCriticalSource
Zyxel VMG1312-B10D - Login DetectionIdentify web-based control panelsInfoSource
Zyxel VSG1432-B101 - Login DetectionIdentify web-based control panelsInfoSource
airCube Dashboard Login Panel - DetectIdentify web-based control panelsInfoSource
airCube Login - DetectIdentify web-based control panelsInfoSource
bloofoxCMS Default CredentialsIdentify default logins in web-based control panelsHighSource
cPanel API Codes Panel - DetectIdentify web-based control panelsInfoSource
coreBOS Panel - DetectIdentify web-based control panelsInfoSource
dbt Docs Panel - DetectIdentify web-based control panelsInfoSource
dotAdmin Login Panel- DetectIdentify web-based control panelsInfoSource
draw.io Flowchart Maker Panel - DetectIdentify web-based control panelsInfoSource
eArcu Panel - DetectIdentify web-based control panelsInfoSource
eMerge E3 1.00-06 - Remote Code ExecutionCVE-2019-7256Identify critical remote vulnerabilitiesCriticalSource
eMessage Login Panel - DetectIdentify web-based control panelsInfoSource
eZ Publish Login Panel - DetectIdentify web-based control panelsInfoSource
iClock Automatic Data Master Server Admin Panel - DetectIdentify web-based control panelsInfoSource
iSAMS Panel - DetectIdentify web-based control panelsInfoSource
iSpy 7.2.2.0 - Authentication BypassCVE-2022-29775Identify critical remote vulnerabilitiesCriticalSource
iTop - User Enumeration via REST EndpointCVE-2024-51739Identify critical remote vulnerabilitiesHighSource
iTop Hub Connector - Information DisclosureCVE-2024-32870Identify critical remote vulnerabilitiesMediumSource
iXBus Login Panel - DetectIdentify web-based control panelsInfoSource
ipTIME A2004 - Unauthorized AccessCVE-2024-54763Identify critical remote vulnerabilitiesMediumSource
ipTIME A2004 - Unauthorized AccessCVE-2024-54764Identify critical remote vulnerabilitiesMediumSource
kkFileView Panel - DetectIdentify web-based control panelsInfoSource
mTheme Unus < 2.3 - Directory TraversalCVE-2015-9406Identify critical remote vulnerabilitiesHighSource
macOS Server Panel - DetectIdentify web-based control panelsInfoSource
mantisbt - Anonymous LoginIdentify default logins in web-based control panelsMediumSource
modoboa 2.0.4 - Admin TakeOverCVE-2023-0777Identify critical remote vulnerabilitiesCriticalSource
myLittleAdmin Login Panel - DetectIdentify web-based control panelsInfoSource
myLittleBackup Panel - DetectIdentify web-based control panelsInfoSource
n8n Panel - DetectIdentify web-based control panelsInfoSource
n8n Webhooks - Remote Code ExecutionCVE-2026-21858Identify critical remote vulnerabilitiesCriticalSource
ngSurvey Login Panel - DetectIdentify web-based control panelsInfoSource
nginxWebUI ≤ 3.5.0 - Remote Command ExecutionIdentify critical remote vulnerabilitiesCriticalSource
nginxWebUI ≤ 3.5.0 runCmd - Remote Command ExecutionIdentify critical remote vulnerabilitiesCriticalSource
noVNC Login Panel - DetectIdentify web-based control panelsInfoSource
nostromo 1.9.6 - Remote Code ExecutionCVE-2019-16278Identify critical remote vulnerabilitiesCriticalSource
openSIS Classic v9.1 - SQL InjectionCVE-2024-51211Identify critical remote vulnerabilitiesCriticalSource
openSIS v9.0 - Path TraversalCVE-2023-38879Identify critical remote vulnerabilitiesHighSource
osTicket Installer Panel - DetectIdentify web-based control panelsCriticalSource
osTicket Login Panel - DetectIdentify web-based control panelsInfoSource
ownCloud Server - DetectionIdentify web-based control panelsInfoSource
pCOWeb - Default-LoginIdentify default logins in web-based control panelsHighSource
pCOWeb Panel - DetectIdentify web-based control panelsInfoSource
pREST < 1.5.4 - SQL Injection Via Authentication BypassIdentify critical remote vulnerabilitiesCriticalSource
pfSense Login Panel - DetectIdentify web-based control panelsInfoSource
phpCollab Login Panel - DetectIdentify web-based control panelsInfoSource
phpLDAPadmin <= 1.2.3 - Reflected XSSCVE-2017-11107Identify critical remote vulnerabilitiesMediumSource
phpMiniAdmin Login Panel - DetectIdentify web-based control panelsInfoSource
phpMyAdmin - Default LoginIdentify default logins in web-based control panelsHighSource
phpMyAdmin Full Path DisclosureIdentify critical remote vulnerabilitiesLowSource
phpMyAdmin Panel - DetectIdentify web-based control panelsInfoSource
phpMyFAQ - Configuration Backup DisclosureCVE-2025-69200Identify critical remote vulnerabilitiesHighSource
phpPgAdmin Login Panel - DetectIdentify web-based control panelsInfoSource
playSMS <1.4.3 - Remote Code ExecutionCVE-2020-8644Identify critical remote vulnerabilitiesCriticalSource
pyLoad Flask Config - Access ControlCVE-2024-21644Identify critical remote vulnerabilitiesHighSource
qBittorrent Web UI Panel - DetectIdentify web-based control panelsInfoSource
qdPM 9.2 - Directory TraversalCVE-2023-45855Identify critical remote vulnerabilitiesHighSource
qdPM Login PanelIdentify web-based control panelsInfoSource
rConfig - Default LoginIdentify default logins in web-based control panelsHighSource
rConfig 3.9 - SQL InjectionCVE-2020-10220Identify critical remote vulnerabilitiesCriticalSource
rConfig 3.9.4 - SQL InjectionCVE-2020-10546Identify critical remote vulnerabilitiesCriticalSource
rConfig 3.9.4 - SQL InjectionCVE-2020-10547Identify critical remote vulnerabilitiesCriticalSource
rConfig 3.9.4 - SQL InjectionCVE-2020-10548Identify critical remote vulnerabilitiesCriticalSource
rConfig <=3.9.4 - SQL InjectionCVE-2020-10549Identify critical remote vulnerabilitiesCriticalSource
temBoard Panel - DetectIdentify web-based control panelsInfoSource
tshirtecommerce PrestaShop Module - SQL InjectionCVE-2023-27638Identify critical remote vulnerabilitiesCriticalSource
txAdmin Panel - DetectIdentify web-based control panelsInfoSource
vBulletin 5.0.0-5.5.4 - Remote Command ExecutionCVE-2019-16759Identify critical remote vulnerabilitiesCriticalSource
vBulletin 5.5.4 - 5.6.2- Remote Command ExecutionCVE-2020-17496Identify critical remote vulnerabilitiesCriticalSource
vBulletin <= 4.2.3 - SQL InjectionCVE-2016-6195Identify critical remote vulnerabilitiesCriticalSource
vBulletin SQL InjectionCVE-2020-12720Identify critical remote vulnerabilitiesCriticalSource
vRealize Hyperic Login Panel - DetectIdentify web-based control panelsInfoSource
vRealize Log Insight - Panel DetectIdentify web-based control panelsInfoSource
webp_server_go 0.4.0 - Path TraversalCVE-2021-46104Identify critical remote vulnerabilitiesHighSource
wpDiscuz <= 5.3.5 - SQL InjectionCVE-2020-13640Identify critical remote vulnerabilitiesCriticalSource
zhttpd - Local File InclusionIdentify critical remote vulnerabilitiesHighSource
Р7-Office 12.5 - Cross-Site ScriptingIdentify critical remote vulnerabilitiesMediumSource