{"ip":"109.224.17.213","total_events":8884,"verdict":{"verdict":"malicious","label":"Exploit attempts observed","detail":"82 exploit-path hits","confidence":"high","network_type":null,"why":["82 request(s) matched a known exploit path.","Body-carrying methods (POST/PUT/PATCH/DELETE) seen: payload delivery, not just recon.","5+ hits raise confidence to high.","Not in any known-scanner range.","Sent 2,104,823 bytes: sustained payload delivery, not a single opportunistic request."],"engagement":{"level":"payload","label":"Sustained payload","detail":"2,104,823 bytes sent","bytes_sent":2104823,"session_seconds":40,"persistent":false}},"first_seen":"2026-05-05T12:36:41","last_seen":"2026-08-20T21:21:46","events_24h":3801,"events_7d":8873,"geo":{"country_code":"IQ","country_name":"Iraq","region":"","city":"","lat":33.0,"lon":44.0,"asn":203214,"org":"Hulum Almustakbal Company for Communication Engineering and Services Ltd"},"source_domain":null,"known_scanners":[],"scanner_tag":null,"cve_matches":[{"cve_id":"CVE-2017-1000486","title":"Primetek Primefaces 5.x - Remote Code Execution","severity":"critical","actively_exploited":true,"match_field":"url_path","matched_pattern":"/javax.faces.resource/dynamiccontent.properties.xhtml"},{"cve_id":"CVE-2017-12149","title":"Jboss Application Server - Remote Code Execution","severity":"critical","actively_exploited":true,"match_field":"url_path","matched_pattern":"/invoker/EJBInvokerServlet"},{"cve_id":"CVE-2017-15944","title":"Palo Alto Network PAN-OS - Remote Code Execution","severity":"critical","actively_exploited":true,"match_field":"url_path","matched_pattern":"/esp/cms_changeDeviceContext.esp?device=aaaaa:a%27\";user|s.\"1337\";"},{"cve_id":"CVE-2017-18362","title":"Kaseya VSA 2017 ConnectWise ManagedITSync - Remote Code Execution","severity":"critical","actively_exploited":true,"match_field":"url_path","matched_pattern":"/KaseyaCwWebService/ManagedIT.asmx"},{"cve_id":"CVE-2017-9791","title":"Apache Struts2 S2-053 - Remote Code Execution","severity":"critical","actively_exploited":true,"match_field":"url_path","matched_pattern":"/integration/saveGangster.action"},{"cve_id":"CVE-2018-15961","title":"Adobe ColdFusion - Unrestricted File Upload Remote Code Execution","severity":"critical","actively_exploited":true,"match_field":"url_path","matched_pattern":"/cf_scripts/scripts/ajax/ckeditor/plugins/filemanager/upload.cfm"},{"cve_id":"CVE-2018-6961","title":"VMware NSX SD-WAN Edge - Command Injection","severity":"critical","actively_exploited":true,"match_field":"url_path","matched_pattern":"/scripts/ajaxPortal.lua"},{"cve_id":"CVE-2018-7600","title":"Drupal - Remote Code Execution","severity":"critical","actively_exploited":true,"match_field":"url_path","matched_pattern":"/user/register"},{"cve_id":"CVE-2019-10068","title":"Kentico CMS Insecure Deserialization Remote Code Execution","severity":"critical","actively_exploited":true,"match_field":"url_path","matched_pattern":"/CMSPages/Staging/SyncServer.asmx/ProcessSynchronizationTaskData"},{"cve_id":"CVE-2019-11580","title":"Atlassian Crowd and Crowd Data Center - Unauthenticated Remote Code Execution","severity":"critical","actively_exploited":true,"match_field":"url_path","matched_pattern":"/crowd/admin/uploadplugin.action"},{"cve_id":"CVE-2019-12989","title":"Citrix SD-WAN and NetScaler SD-WAN - SQL Injection","severity":"critical","actively_exploited":true,"match_field":"url_path","matched_pattern":"/sdwan/nitro/v1/config/get_package_file"},{"cve_id":"CVE-2019-16278","title":"nostromo 1.9.6 - Remote Code Execution","severity":"critical","actively_exploited":true,"match_field":"url_path","matched_pattern":"/.%0d./.%0d./.%0d./.%0d./bin/sh"},{"cve_id":"CVE-2019-3396","title":"Atlassian Confluence Server - Path Traversal","severity":"critical","actively_exploited":true,"match_field":"url_path","matched_pattern":"/rest/tinymce/1/macro/preview"},{"cve_id":"CVE-2019-7609","title":"Kibana Timelion - Arbitrary Code Execution","severity":"critical","actively_exploited":true,"match_field":"url_path","matched_pattern":"/api/timelion/run"},{"cve_id":"CVE-2019-9670","title":"Synacor Zimbra Collaboration <8.7.11p10 - XML External Entity Injection","severity":"critical","actively_exploited":true,"match_field":"url_path","matched_pattern":"/Autodiscover/Autodiscover.xml"},{"cve_id":"CVE-2020-12641","title":"Roundcube Webmail - Command Injection","severity":"critical","actively_exploited":true,"match_field":"url_path","matched_pattern":"/installer/index.php"},{"cve_id":"CVE-2020-15415","title":"DrayTek Vigor - Command Injection","severity":"critical","actively_exploited":true,"match_field":"url_path","matched_pattern":"/cgi-bin/mainfunction.cgi/cvmcfgupload"},{"cve_id":"CVE-2020-15505","title":"MobileIron Core & Connector <= v10.6 & Sentry <= v9.8 - Remote Code Execution","severity":"critical","actively_exploited":true,"match_field":"url_path","matched_pattern":"/mifs/.;/services/LogService"},{"cve_id":"CVE-2020-25213","title":"WordPress File Manager Plugin - Remote Code Execution","severity":"critical","actively_exploited":true,"match_field":"url_path","matched_pattern":"/wp-content/plugins/wp-file-manager/lib/php/connector.minimal.php"},{"cve_id":"CVE-2020-8515","title":"DrayTek - Remote Code Execution","severity":"critical","actively_exploited":true,"match_field":"url_path","matched_pattern":"/cgi-bin/mainfunction.cgi"},{"cve_id":"CVE-2017-12615","title":"Apache Tomcat Servers - Remote Code Execution","severity":"high","actively_exploited":true,"match_field":"url_path","matched_pattern":"/poc.jsp?cmd=cat+%2Fetc%2Fpasswd"},{"cve_id":"CVE-2019-9082","title":"ThinkPHP < 3.2.4 - Remote Code Execution","severity":"high","actively_exploited":true,"match_field":"url_path","matched_pattern":"/index.php?s=/Index/\\think\\app/invokefunction&function=call_user_func_array&vars[0]=system&vars[1][]=echo%20thinkphp%20%"},{"cve_id":"CVE-2019-9621","title":"Zimbra Collaboration Suite - SSRF","severity":"high","actively_exploited":true,"match_field":"url_path","matched_pattern":"/autodiscover"},{"cve_id":"CVE-2020-10199","title":"Sonatype Nexus Repository Manager 3 - Remote Code Execution","severity":"high","actively_exploited":true,"match_field":"url_path","matched_pattern":"/service/rest/beta/repositories/bower/group"},{"cve_id":"CVE-2020-11978","title":"Apache Airflow <=1.10.10 - Remote Code Execution","severity":"high","actively_exploited":true,"match_field":"url_path","matched_pattern":"/api/experimental/dags/example_trigger_target_dag/dag_runs"},{"cve_id":"CVE-2020-14883","title":"Oracle Fusion Middleware WebLogic Server Administration Console - Remote Code Execution","severity":"high","actively_exploited":true,"match_field":"url_path","matched_pattern":"/console/images/%252e%252e%252fconsole.portal"},{"cve_id":"CVE-2020-1956","title":"Apache Kylin 3.0.1 - Command Injection Vulnerability","severity":"high","actively_exploited":true,"match_field":"url_path","matched_pattern":"/kylin/api/user/authentication"},{"cve_id":"CVE-2010-0219","title":"Apache Axis2 Default Login","severity":"critical","actively_exploited":false,"match_field":"url_path","matched_pattern":"/axis2-admin/login"},{"cve_id":"CVE-2014-9614","title":"Netsweeper 4.0.5 - Default Weak Account","severity":"critical","actively_exploited":false,"match_field":"url_path","matched_pattern":"/webadmin/auth/verification.php"},{"cve_id":"CVE-2016-15042","title":"WordPress Frontend File Manager < 4.0 & N-Media Post Frontend < 1.1 - Arbitrary File Upload","severity":"critical","actively_exploited":false,"match_field":"url_path","matched_pattern":"/wp-content/uploads/post_files"},{"cve_id":"CVE-2016-5649","title":"NETGEAR DGN2200 / DGND3700 - Admin Password Disclosure","severity":"critical","actively_exploited":false,"match_field":"url_path","matched_pattern":"/BSW_cxttongr.htm"},{"cve_id":"CVE-2017-12635","title":"Apache CouchDB 1.7.0 / 2.x < 2.1.1 - Remote Privilege Escalation","severity":"critical","actively_exploited":false,"match_field":"url_path","matched_pattern":"/_users/org.couchdb.user:poc"},{"cve_id":"CVE-2017-5983","title":"JIRA Workflow Designer Plugin in Atlassian JIRA Server > 6.3.0 - Remote Code Execution (XXE)","severity":"critical","actively_exploited":false,"match_field":"url_path","matched_pattern":"/jira/secure/Dashboard.jspa"},{"cve_id":"CVE-2018-11686","title":"FlexPaper/FlowPaper 2.3.6 - Remote Code Execution","severity":"critical","actively_exploited":false,"match_field":"url_path","matched_pattern":"/php/config/output.txt"},{"cve_id":"CVE-2018-1217","title":"Dell EMC Avamar and Integrated Data Protection Appliance Installation Manager - Invalid Access Control","severity":"critical","actively_exploited":false,"match_field":"url_path","matched_pattern":"/avi/avigui/avigwt"},{"cve_id":"CVE-2018-14728","title":"Responsive filemanager 9.13.1 Server-Side Request Forgery","severity":"critical","actively_exploited":false,"match_field":"url_path","matched_pattern":"/filemanager/upload.php"},{"cve_id":"CVE-2018-17153","title":"Western Digital MyCloud NAS - Authentication Bypass","severity":"critical","actively_exploited":false,"match_field":"url_path","matched_pattern":"/web/google_analytics.php"},{"cve_id":"CVE-2018-17207","title":"WordPress Duplicator Plugin < 1.2.42 - Arbitrary Code Execution","severity":"critical","actively_exploited":false,"match_field":"url_path","matched_pattern":"/installer-backup.php"},{"cve_id":"CVE-2018-17431","title":"Comodo Unified Threat Management Web Console - Remote Code Execution","severity":"critical","actively_exploited":false,"match_field":"url_path","matched_pattern":"/manage/webshell/u?s=5&w=218&h=15&k=%0a&l=62&_=5621298674064"},{"cve_id":"CVE-2018-19127","title":"PHPCMS 2008 - Remote Code Execution via Template Injection","severity":"critical","actively_exploited":false,"match_field":"url_path","matched_pattern":"/data/cache_template/rss.tpl.php"},{"cve_id":"CVE-2018-20526","title":"Roxy Fileman 1.4.5 - Unrestricted File Upload","severity":"critical","actively_exploited":false,"match_field":"url_path","matched_pattern":"/php/upload.php"},{"cve_id":"CVE-2018-20985","title":"WordPress Payeezy Pay <=2.97 - Local File Inclusion","severity":"critical","actively_exploited":false,"match_field":"url_path","matched_pattern":"/wp-content/plugins/wp-payeezy-pay/donate.php"},{"cve_id":"CVE-2018-25114","title":"osCommerce 2.3.4.1 - Remote Code Execution","severity":"critical","actively_exploited":false,"match_field":"url_path","matched_pattern":"/install/includes/configure.php"},{"cve_id":"CVE-2018-2894","title":"Oracle WebLogic Server - Remote Code Execution","severity":"critical","actively_exploited":false,"match_field":"url_path","matched_pattern":"/ws_utc/resources/setting/keystore"},{"cve_id":"CVE-2019-12990","title":"Citrix SD-WAN Center - Local File Inclusion","severity":"critical","actively_exploited":false,"match_field":"url_path","matched_pattern":"/Collector/appliancesettings/applianceSettingsFileTransfer"},{"cve_id":"CVE-2019-13372","title":"D-Link Central WiFi Manager CWM(100) - Remote Code Execution","severity":"critical","actively_exploited":false,"match_field":"url_path","matched_pattern":"/index.php/Index/index"},{"cve_id":"CVE-2019-17444","title":"Jfrog Artifactory <6.17.0 - Default Admin Password","severity":"critical","actively_exploited":false,"match_field":"url_path","matched_pattern":"/ui/auth/login"},{"cve_id":"CVE-2019-1821","title":"Cisco Prime Infrastructure and Cisco Evolved Programmable Network Manager - Remote Code Execution","severity":"critical","actively_exploited":false,"match_field":"url_path","matched_pattern":"/servlet/UploadServlet"},{"cve_id":"CVE-2019-18818","title":"strapi CMS <3.0.0-beta.17.5 - Admin Password Reset","severity":"critical","actively_exploited":false,"match_field":"url_path","matched_pattern":"/admin/auth/reset-password"},{"cve_id":"CVE-2019-2729","title":"Oracle WebLogic Server Administration Console - Remote Code Execution","severity":"critical","actively_exploited":false,"match_field":"url_path","matched_pattern":"/_async/favicon.ico"},{"cve_id":"CVE-2019-5127","title":"YouPHPTube Encoder 2.3 - Remote Command Injection","severity":"critical","actively_exploited":false,"match_field":"url_path","matched_pattern":"/objects/getImage.php"},{"cve_id":"CVE-2019-5434","title":"Revive Adserver 4.2 - Remote Code Execution","severity":"critical","actively_exploited":false,"match_field":"url_path","matched_pattern":"/adxmlrpc.php"},{"cve_id":"CVE-2019-7276","title":"Optergy Proton/Enterprise - Unauthenticated RCE via Backdoor Console","severity":"critical","actively_exploited":false,"match_field":"url_path","matched_pattern":"/tools/ajax/ConsoleResult.html"},{"cve_id":"CVE-2019-9733","title":"JFrog Artifactory 6.7.3 - Admin Login Bypass","severity":"critical","actively_exploited":false,"match_field":"url_path","matched_pattern":"/artifactory/ui/auth/login"},{"cve_id":"CVE-2020-11546","title":"SuperWebmailer 7.21.0.01526 - Remote Code Execution","severity":"critical","actively_exploited":false,"match_field":"url_path","matched_pattern":"/mailingupgrade.php"},{"cve_id":"CVE-2020-13167","title":"Netsweeper <=6.4.3 - Python Code Injection","severity":"critical","actively_exploited":false,"match_field":"url_path","matched_pattern":"/webadmin/out"},{"cve_id":"CVE-2020-35729","title":"Klog Server <=2.41 - Unauthenticated Command Injection","severity":"critical","actively_exploited":false,"match_field":"url_path","matched_pattern":"/actions/authenticate.php"},{"cve_id":"CVE-2024-51568","title":"CyberPanel - Command Injection","severity":"critical","actively_exploited":false,"match_field":"url_path","matched_pattern":"/filemanager/upload"},{"cve_id":"CVE-2026-5718","title":"Drag and Drop Multiple File Upload - CF7 <= 1.3.9.6 - Remote Code Execution","severity":"critical","actively_exploited":false,"match_field":"url_path","matched_pattern":"/wp-content/uploads/wp_dndcf7_uploads"},{"cve_id":"CVE-2015-7245","title":"D-Link DVG-N5402SP - Local File Inclusion","severity":"high","actively_exploited":false,"match_field":"url_path","matched_pattern":"/cgibin/webproc"},{"cve_id":"CVE-2016-10960","title":"WordPress wSecure Lite < 2.4 - Remote Code Execution","severity":"high","actively_exploited":false,"match_field":"url_path","matched_pattern":"/wp-content/plugins/wsecure/wsecure-config.php"},{"cve_id":"CVE-2016-3081","title":"Apache S2-032 Struts - Remote Code Execution","severity":"high","actively_exploited":false,"match_field":"url_path","matched_pattern":"/index.action?method:%23_memberAccess%3d@ognl.OgnlContext@DEFAULT_MEMBER_ACCESS,%23res%3d%40org.apache.struts2.ServletAc"},{"cve_id":"CVE-2017-17762","title":"Episerver 7 - Blind XML External Entity Injection","severity":"high","actively_exploited":false,"match_field":"url_path","matched_pattern":"/util/xmlrpc/Handler.ashx"},{"cve_id":"CVE-2018-1000130","title":"Jolokia Agent - JNDI Code Injection","severity":"high","actively_exploited":false,"match_field":"url_path","matched_pattern":"/jolokia/read/getDiagnosticOptions"},{"cve_id":"CVE-2018-10737","title":"NagiosXI <= 5.4.12 logbook.php SQL injection","severity":"high","actively_exploited":false,"match_field":"url_path","matched_pattern":"/nagiosql/admin/logbook.php"},{"cve_id":"CVE-2018-10738","title":"NagiosXI <= 5.4.12 menuaccess.php - SQL injection","severity":"high","actively_exploited":false,"match_field":"url_path","matched_pattern":"/nagiosql/admin/menuaccess.php"},{"cve_id":"CVE-2018-11222","title":"Pandora FMS <=7.0NG.722 - Remote Code Execution","severity":"high","actively_exploited":false,"match_field":"url_path","matched_pattern":"/pandora_console/ajax.php"},{"cve_id":"CVE-2018-11231","title":"Opencart Divido - Sql Injection","severity":"high","actively_exploited":false,"match_field":"url_path","matched_pattern":"/upload/index.php"},{"cve_id":"CVE-2018-12296","title":"Seagate NAS OS 4.3.15.1 - Server Information Disclosure","severity":"high","actively_exploited":false,"match_field":"url_path","matched_pattern":"/api/external/7.0/system.System.get_infos"},{"cve_id":"CVE-2018-2791","title":"Oracle Fusion Middleware WebCenter Sites - Cross-Site Scripting","severity":"high","actively_exploited":false,"match_field":"url_path","matched_pattern":"/cs/Satellite?destpage=\"<h1xxx\"><script>alert(document.domain)</script>&pagename=OpenMarket%2FXcelerate%2FUIFramework%2F"},{"cve_id":"CVE-2018-7467","title":"AxxonSoft Axxon Next - Local File Inclusion","severity":"high","actively_exploited":false,"match_field":"url_path","matched_pattern":"//css//..%2f..%2f..%2f..%2f..%2f..%2f..%2f..%2f..%2f..%2f..%2f..%2f..%2f..%2f..%2f..%2f..%2f..%2fwindows\\win.ini"},{"cve_id":"CVE-2018-7719","title":"Acrolinx Server <5.2.5 - Local File Inclusion","severity":"high","actively_exploited":false,"match_field":"url_path","matched_pattern":"/..\\..\\..\\..\\..\\..\\..\\..\\..\\..\\..\\..\\..\\..\\windows\\win.ini"},{"cve_id":"CVE-2018-8033","title":"Apache OFBiz - XML External Entity Injection","severity":"high","actively_exploited":false,"match_field":"url_path","matched_pattern":"/webtools/control/httpService"},{"cve_id":"CVE-2019-11253","title":"Kubernetes API Server - YAML Parsing DoS (Billion Laughs)","severity":"high","actively_exploited":false,"match_field":"url_path","matched_pattern":"/apis/authorization.k8s.io/v1/selfsubjectaccessreviews"},{"cve_id":"CVE-2019-17538","title":"Jiangnan Online Judge 0.8.0 - Local File Inclusion","severity":"high","actively_exploited":false,"match_field":"url_path","matched_pattern":"/jnoj/web/polygon/problem/viewfile?id=1&name=../../../../../../../etc/passwd"},{"cve_id":"CVE-2019-18922","title":"Allied Telesis AT-GS950/8 - Local File Inclusion","severity":"high","actively_exploited":false,"match_field":"url_path","matched_pattern":"/../../../../../../etc/passwd"},{"cve_id":"CVE-2019-20224","title":"Pandora FMS 7.0NG - Remote Command Injection","severity":"high","actively_exploited":false,"match_field":"url_path","matched_pattern":"/pandora_console/index.php"},{"cve_id":"CVE-2019-6715","title":"W3 Total Cache 0.9.2.6-0.9.3 - Unauthenticated File Read / Directory Traversal","severity":"high","actively_exploited":false,"match_field":"url_path","matched_pattern":"/wp-content/plugins/w3-total-cache/pub/sns.php"},{"cve_id":"CVE-2019-7315","title":"Genie Access WIP3BVAF IP Camera - Local File Inclusion","severity":"high","actively_exploited":false,"match_field":"url_path","matched_pattern":"/../../../../../etc/passwd"},{"cve_id":"CVE-2020-11991","title":"Apache Cocoon 2.1.12 - XML Injection","severity":"high","actively_exploited":false,"match_field":"url_path","matched_pattern":"/v2/api/product/manger/getInfo"},{"cve_id":"CVE-2020-13851","title":"Artica Pandora FMS 7.44 - Remote Code Execution","severity":"high","actively_exploited":false,"match_field":"url_path","matched_pattern":"/pandora_console/ajax.php?page=include/ajax/events&perform_event_response=10000000&target=cat+/etc/passwd&response_id=1"},{"cve_id":"CVE-2020-17505","title":"Artica Web Proxy 4.30 - OS Command Injection","severity":"high","actively_exploited":false,"match_field":"url_path","matched_pattern":"/cyrus.index.php?service-cmds-peform=%7C%7Cwhoami%7C%7C"},{"cve_id":"CVE-2020-17518","title":"Apache Flink 1.5.1 - Local File Inclusion","severity":"high","actively_exploited":false,"match_field":"url_path","matched_pattern":"/jobmanager/logs/..%252f..%252f..%252f..%252f..%252f..%252f..%252f..%252f..%252f..%252f..%252f..%252ftmp%252fpoc"},{"cve_id":"CVE-2020-24579","title":"D-Link DSL 2888a - Authentication Bypass/Remote Command Execution","severity":"high","actively_exploited":false,"match_field":"url_path","matched_pattern":"/cgi-bin/execute_cmd.cgi?timestamp=1589333279490&cmd=cat%20/etc/passwd"},{"cve_id":"CVE-2020-25780","title":"Commvault CommCell - Local File Inclusion","severity":"high","actively_exploited":false,"match_field":"url_path","matched_pattern":"/SearchSvc/CVSearchService.svc"},{"cve_id":"CVE-2023-39141","title":"Aria2 WebUI - Path traversal","severity":"high","actively_exploited":false,"match_field":"url_path","matched_pattern":"/../../../../etc/passwd"},{"cve_id":"CVE-2025-3515","title":"Contact Form 7 Drag and Drop Multiple File Upload - Arbitrary File Upload","severity":"high","actively_exploited":false,"match_field":"url_path","matched_pattern":"/wp-content/uploads/wp_dndcf7_uploads/wpcf7-files"},{"cve_id":"CVE-2007-4556","title":"OpenSymphony XWork/Apache Struts2 - Remote Code Execution","severity":"medium","actively_exploited":false,"match_field":"url_path","matched_pattern":"/login.action"},{"cve_id":"CVE-2022-31798","title":"Nortek Linear eMerge E3-Series - Cross-Site Scripting","severity":"medium","actively_exploited":false,"match_field":"url_path","matched_pattern":"/card_scan.php"},{"cve_id":"CVE-2022-37153","title":"Artica Proxy 4.30.000000 - Cross-Site Scripting","severity":"medium","actively_exploited":false,"match_field":"url_path","matched_pattern":"/fw.login.php"}],"malware":[],"top_ports":[{"port":7001,"proto":"tcp","label":"WebLogic","count":447},{"port":443,"proto":"tcp","label":"HTTPS","count":395},{"port":8009,"proto":"tcp","label":"","count":371},{"port":8080,"proto":"tcp","label":"HTTP-alt","count":362},{"port":8291,"proto":"tcp","label":"","count":354},{"port":61616,"proto":"tcp","label":"ActiveMQ","count":352},{"port":2375,"proto":"tcp","label":"Docker","count":352},{"port":5984,"proto":"tcp","label":"CouchDB","count":352},{"port":2376,"proto":"tcp","label":"Docker-TLS","count":352},{"port":11211,"proto":"tcp","label":"Memcached","count":352},{"port":161,"proto":"tcp","label":"SNMP","count":352},{"port":7002,"proto":"tcp","label":"","count":352},{"port":3306,"proto":"tcp","label":"MySQL","count":352},{"port":4243,"proto":"tcp","label":"","count":352},{"port":8088,"proto":"tcp","label":"Hadoop","count":352}],"fingerprints":{"ssh_hassh":[],"tls_ja4":["t13i130900_f57a46bbacb6_e7c285222651","t13i251000_b78ed14e2fd0_ab7e3b40a677","t13i3111h1_e8f1e7e78f70_b26ce05bbdd6","t12i210500_fc5fe67d2e46_e51b7354d87f"],"tls_ja3":["416eca07dcaad72dec6f76d1277b3eff","8e081150dabad331299ed52a4aea0a51"],"ja4h":["ge11nn0400_88d30a62b7ad","ge11nn0300_0db47b7d240d","ge11nn0100_4740ae6347b0","po11nn06en_55679cbb40e0","po11nn0500_b4ba55311b46"]},"fingerprint_peers":{"t13i130900_f57a46bbacb6_e7c285222651":3706,"t13i251000_b78ed14e2fd0_ab7e3b40a677":69,"t12i210500_fc5fe67d2e46_e51b7354d87f":2,"t13i3111h1_e8f1e7e78f70_b26ce05bbdd6":7,"ge11nn0300_0db47b7d240d":5528,"ge11nn0100_4740ae6347b0":604,"po11nn0500_b4ba55311b46":164,"po11nn06en_55679cbb40e0":3,"ge11nn0400_88d30a62b7ad":4888},"user_agents":["Mozilla/5.0 (Macintosh; Intel Mac OS X 10.13; rv:109.0) Gecko/20100101 Firefox/115.0","Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.8 Safari/605.1.15","Mozilla/5.0 (ZZ; Linux i686) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/138.0.0.0 Safari/537.36","Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:134.0) Gecko/20100101 Firefox/134.0","Mozilla/5.0 (Debian; Linux i686) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/137.0.0.0 Safari/537.36","Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.32 Safari/537.36","Mozilla/5.0 (CentOS; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/135.0.0.0 Safari/537.36"],"timeline":[{"date":"2026-08-19","count":7121},{"date":"2026-08-20","count":1752}],"recent_events":[{"timestamp":"2026-08-20T21:21:46","port":9200,"proto":"tcp","app_proto":"tls","app_protocol":"http","host":"<HONEYPOT>","headers":"{\"accept\":\"*/*\",\"accept-encoding\":\"gzip\",\"accept-language\":\"en\",\"content-length\":\"50\",\"content-type\":\"application/json\",\"host\":\"<HONEYPOT>:9200\",\"user-agent\":\"Mozilla/5.0 (X11; Linux i686; rv:1.9.5.20) Gecko/ Firefox/3.6.4\"}","body":"{\r\n  \"token\": {\r\n    \"$func\": \"var_dump\"\r\n  }\r\n}\r\n","sni":"","tls_cipher":"TLS_AES_128_GCM_SHA256","tls_version":"TLSv1.3","alpn":[],"url_path":"/auth/newpassword","summary":"","payload_hex":"504f5354202f617574682f6e657770617373776f726420485454502f312e310d0a486f73743a20<HONEYPOT>3a393230300d0a557365722d4167656e743a204d6f7a696c6c612f352e3020285831313b204c696e757820693638363b2072763a312e392e352e323029204765636b6f2f2046697265666f782f332e362e340d0a436f6e74656e742d4c656e6774683a2035300d0a4163636570743a202a2f2a0d0a4163636570742d4c616e67756167653a20656e0d0a436f6e74656e742d547970653a206170706c69636174696f6e2f6a736f6e0d0a4163636570742d456e636f64696e673a20677a69700d0a0d0a7b0d0a202022746f6b656e223a207b0d0a20202020222466756e63223a20227661725f64756d70220d0a20207d0d0a7d0d0a","method":"POST","user_agent":"Mozilla/5.0 (X11; Linux i686; rv:1.9.5.20) Gecko/ Firefox/3.6.4","ja3":"416eca07dcaad72dec6f76d1277b3eff","session":"b466e2bb-da7d-4529-9d2a-e88f3e8050ab","seq":1,"duration_ms":100,"bytes_in":297,"bytes_out":79},{"timestamp":"2026-08-20T21:21:08","port":443,"proto":"tcp","app_proto":"tls","app_protocol":"http","host":"<HONEYPOT>","headers":"{\"accept\":\"*/*\",\"accept-encoding\":\"gzip\",\"accept-language\":\"en\",\"host\":\"<HONEYPOT>:443\",\"user-agent\":\"Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/136.0.0.0 Safari/537.36\"}","body":"","sni":"","tls_cipher":"TLS_AES_128_GCM_SHA256","tls_version":"TLSv1.3","alpn":[],"url_path":"/","summary":"","payload_hex":"474554202f20485454502f312e310d0a486f73743a20<HONEYPOT>3a3434330d0a557365722d4167656e743a204d6f7a696c6c612f352e3020285831313b204c696e7578207838365f363429204170706c655765624b69742f3533372e333620284b48544d4c2c206c696b65204765636b6f29204368726f6d652f3133362e302e302e30205361666172692f3533372e33360d0a4163636570743a202a2f2a0d0a4163636570742d4c616e67756167653a20656e0d0a4163636570742d456e636f64696e673a20677a69700d0a0d0a","method":"GET","user_agent":"Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/136.0.0.0 Safari/537.36","ja3":"416eca07dcaad72dec6f76d1277b3eff","session":"2cc39408-43c2-4e7e-9e71-56cc3b2da74a","seq":1,"duration_ms":100,"bytes_in":215,"bytes_out":79},{"timestamp":"2026-08-20T21:21:02","port":80,"proto":"tcp","app_proto":"tls","app_protocol":"http","host":"<HONEYPOT>","headers":"{\"accept-encoding\":\"gzip\",\"host\":\"<HONEYPOT>:80\",\"user-agent\":\"Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36\"}","body":"","sni":"","tls_cipher":"TLS_AES_128_GCM_SHA256","tls_version":"TLSv1.3","alpn":[],"url_path":"/file/hLyeXg.txt","summary":"","payload_hex":"474554202f66696c652f684c796558672e74787420485454502f312e310d0a486f73743a20<HONEYPOT>3a38300d0a557365722d4167656e743a204d6f7a696c6c612f352e30202857696e646f7773204e542031302e303b2057696e36343b2078363429204170706c655765624b69742f3533372e333620284b48544d4c2c206c696b65204765636b6f29204368726f6d652f37382e302e333930342e313038205361666172692f3533372e33360d0a4163636570742d456e636f64696e673a20677a69700d0a0d0a","method":"GET","user_agent":"Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36","ja3":"416eca07dcaad72dec6f76d1277b3eff","session":"e6596a57-f5fc-4ff1-9f1c-febefbf9ea1c","seq":2,"duration_ms":1933,"bytes_in":807,"bytes_out":158},{"timestamp":"2026-08-20T21:21:01","port":8080,"proto":"tcp","app_proto":"tls","app_protocol":"http","host":"<HONEYPOT>","headers":"{\"accept-encoding\":\"gzip\",\"host\":\"<HONEYPOT>:8080\",\"user-agent\":\"Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/16.2 Safari/605.1.15\"}","body":"","sni":"","tls_cipher":"TLS_AES_128_GCM_SHA256","tls_version":"TLSv1.3","alpn":[],"url_path":"/","summary":"","payload_hex":"474554202f20485454502f312e310d0a486f73743a20<HONEYPOT>3a383038300d0a557365722d4167656e743a204d6f7a696c6c612f352e3020284d6163696e746f73683b20496e74656c204d6163204f5320582031305f31355f3729204170706c655765624b69742f3630352e312e313520284b48544d4c2c206c696b65204765636b6f292056657273696f6e2f31362e32205361666172692f3630352e312e31350d0a4163636570742d456e636f64696e673a20677a69700d0a0d0a","method":"GET","user_agent":"Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/16.2 Safari/605.1.15","ja3":"416eca07dcaad72dec6f76d1277b3eff","session":"f49aff86-2099-44a5-b457-8070605f8f96","seq":1,"duration_ms":100,"bytes_in":198,"bytes_out":79},{"timestamp":"2026-08-20T21:21:01","port":80,"proto":"tcp","app_proto":"tls","app_protocol":"http","host":"<HONEYPOT>","headers":"{\"accept-encoding\":\"gzip\",\"content-length\":\"378\",\"content-type\":\"application/json\",\"host\":\"<HONEYPOT>:80\",\"user-agent\":\"Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:134.0) Gecko/20100101 Firefox/134.0\"}","body":"{\r\n  \"fileName\": \"& echo \\\"3IAmXzmFmfpnoTsaXbfCsBEmI4b\\\" > hLyeXg.txt && ls\",\r\n  \"geoJsonData\": {\r\n    \"type\": \"FeatureCollection\",\r\n    \"features\": [\r\n      {\r\n        \"type\": \"Feature\",\r\n        \"geometry\": {\r\n          \"type\": \"Point\",\r\n          \"coordinates\": [102.0, 0.5]\r\n        },\r\n        \"properties\": {\r\n          \"prop0\": \"value0\"\r\n        }\r\n      }\r\n    ]\r\n  }\r\n}","sni":"","tls_cipher":"TLS_AES_128_GCM_SHA256","tls_version":"TLSv1.3","alpn":[],"url_path":"/convert","summary":"","payload_hex":"504f5354202f636f6e7665727420485454502f312e310d0a486f73743a20<HONEYPOT>3a38300d0a557365722d4167656e743a204d6f7a696c6c612f352e30202857696e646f7773204e542031302e303b2057696e36343b207836343b2072763a3133342e3029204765636b6f2f32303130303130312046697265666f782f3133342e300d0a436f6e74656e742d4c656e6774683a203337380d0a436f6e74656e742d547970653a206170706c69636174696f6e2f6a736f6e0d0a4163636570742d456e636f64696e673a20677a69700d0a0d0a7b0d0a20202266696c654e616d65223a202226206563686f205c223349416d587a6d466d66706e6f547361586266437342456d4934625c22203e20684c796558672e747874202626206c73222c0d0a20202267656f4a736f6e44617461223a207b0d0a202020202274797065223a202246656174757265436f6c6c656374696f6e222c0d0a20202020226665617475726573223a205b0d0a2020202020207b0d0a20202020202020202274797065223a202246656174757265222c0d0a20202020202020202267656f6d65747279223a207b0d0a202020202020202020202274797065223a2022506f696e74222c0d0a2020202020202020202022636f6f7264696e61746573223a205b3130322e302c20302e355d0d0a20202020202020207d2c0d0a20202020202020202270726f70657274696573223a207b0d0a202020202020202020202270726f7030223a202276616c756530220d0a20202020202020207d0d0a2020202020207d0d0a202020205d0d0a20207d0d0a7d","method":"POST","user_agent":"Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:134.0) Gecko/20100101 Firefox/134.0","ja3":"416eca07dcaad72dec6f76d1277b3eff","session":"e6596a57-f5fc-4ff1-9f1c-febefbf9ea1c","seq":1,"duration_ms":100,"bytes_in":598,"bytes_out":79},{"timestamp":"2026-08-20T21:19:04","port":8080,"proto":"tcp","app_proto":"tls","app_protocol":"http","host":"<HONEYPOT>","headers":"{\"accept-encoding\":\"gzip\",\"host\":\"<HONEYPOT>:8080\",\"user-agent\":\"Mozilla/5.0 (Macintosh; Intel Mac OS X 10.12; rv:109.0) Gecko/20100101 Firefox/115.0\"}","body":"","sni":"","tls_cipher":"TLS_AES_128_GCM_SHA256","tls_version":"TLSv1.3","alpn":[],"url_path":"/admin/index.php?page=home","summary":"","payload_hex":"474554202f61646d696e2f696e6465782e7068703f706167653d686f6d6520485454502f312e310d0a486f73743a20<HONEYPOT>3a383038300d0a557365722d4167656e743a204d6f7a696c6c612f352e3020284d6163696e746f73683b20496e74656c204d6163204f5320582031302e31323b2072763a3130392e3029204765636b6f2f32303130303130312046697265666f782f3131352e300d0a4163636570742d456e636f64696e673a20677a69700d0a0d0a","method":"GET","user_agent":"Mozilla/5.0 (Macintosh; Intel Mac OS X 10.12; rv:109.0) Gecko/20100101 Firefox/115.0","ja3":"416eca07dcaad72dec6f76d1277b3eff","session":"3919e7da-7b9e-4434-b00e-3c24b7705bf2","seq":2,"duration_ms":1961,"bytes_in":498,"bytes_out":158},{"timestamp":"2026-08-20T21:19:03","port":8080,"proto":"tcp","app_proto":"tls","app_protocol":"http","host":"<HONEYPOT>","headers":"{\"accept-encoding\":\"gzip\",\"content-length\":\"46\",\"content-type\":\"application/x-www-form-urlencoded\",\"host\":\"<HONEYPOT>:8080\",\"user-agent\":\"Mozilla/5.0 (Macintosh; Intel Mac OS X 10.13; rv:109.0) Gecko/20100101 Firefox/115.0\"}","body":"username=admin'+or+'1'%3D'1'%23&password=mDcln","sni":"","tls_cipher":"TLS_AES_128_GCM_SHA256","tls_version":"TLSv1.3","alpn":[],"url_path":"/admin/ajax.php?action=login","summary":"","payload_hex":"504f5354202f61646d696e2f616a61782e7068703f616374696f6e3d6c6f67696e20485454502f312e310d0a486f73743a20<HONEYPOT>3a383038300d0a557365722d4167656e743a204d6f7a696c6c612f352e3020284d6163696e746f73683b20496e74656c204d6163204f5320582031302e31333b2072763a3130392e3029204765636b6f2f32303130303130312046697265666f782f3131352e300d0a436f6e74656e742d4c656e6774683a2034360d0a436f6e74656e742d547970653a206170706c69636174696f6e2f782d7777772d666f726d2d75726c656e636f6465640d0a4163636570742d456e636f64696e673a20677a69700d0a0d0a757365726e616d653d61646d696e272b6f722b2731272533442731272532332670617373776f72643d6d44636c6e","method":"POST","user_agent":"Mozilla/5.0 (Macintosh; Intel Mac OS X 10.13; rv:109.0) Gecko/20100101 Firefox/115.0","ja3":"416eca07dcaad72dec6f76d1277b3eff","session":"3919e7da-7b9e-4434-b00e-3c24b7705bf2","seq":1,"duration_ms":100,"bytes_in":308,"bytes_out":79},{"timestamp":"2026-08-20T21:18:53","port":80,"proto":"tcp","app_proto":"tls","app_protocol":"http","host":"<HONEYPOT>","headers":"{\"accept-encoding\":\"gzip\",\"host\":\"<HONEYPOT>:80\",\"user-agent\":\"Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:102.0) Gecko/20100101 Firefox/102.0\"}","body":"","sni":"","tls_cipher":"TLS_AES_128_GCM_SHA256","tls_version":"TLSv1.3","alpn":[],"url_path":"/ebook/bookPerPub.php?pubid=4'","summary":"","payload_hex":"474554202f65626f6f6b2f626f6f6b5065725075622e7068703f70756269643d342720485454502f312e310d0a486f73743a20<HONEYPOT>3a38300d0a557365722d4167656e743a204d6f7a696c6c612f352e3020284d6163696e746f73683b20496e74656c204d6163204f5320582031302e31353b2072763a3130322e3029204765636b6f2f32303130303130312046697265666f782f3130322e300d0a4163636570742d456e636f64696e673a20677a69700d0a0d0a","method":"GET","user_agent":"Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:102.0) Gecko/20100101 Firefox/102.0","ja3":"416eca07dcaad72dec6f76d1277b3eff","session":"c591920b-d0eb-4e3c-83c3-f6d30b575d10","seq":1,"duration_ms":100,"bytes_in":192,"bytes_out":79},{"timestamp":"2026-08-20T21:18:50","port":443,"proto":"tcp","app_proto":"tls","app_protocol":"http","host":"<HONEYPOT>","headers":"{\"accept-encoding\":\"gzip\",\"connection\":\"close\",\"host\":\"<HONEYPOT>:443\",\"user-agent\":\"Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/136.0.0.0 Whale/4.32.315.22 Safari/537.36\"}","body":"","sni":"","tls_cipher":"TLS_AES_128_GCM_SHA256","tls_version":"TLSv1.3","alpn":[],"url_path":"/index.php/catalogsearch/advanced/result/?name=e","summary":"","payload_hex":"474554202f696e6465782e7068702f636174616c6f677365617263682f616476616e6365642f726573756c742f3f6e616d653d6520485454502f312e310d0a486f73743a20<HONEYPOT>3a3434330d0a557365722d4167656e743a204d6f7a696c6c612f352e30202857696e646f7773204e542031302e303b2057696e36343b2078363429204170706c655765624b69742f3533372e333620284b48544d4c2c206c696b65204765636b6f29204368726f6d652f3133362e302e302e30205768616c652f342e33322e3331352e3232205361666172692f3533372e33360d0a436f6e6e656374696f6e3a20636c6f73650d0a4163636570742d456e636f64696e673a20677a69700d0a0d0a","method":"GET","user_agent":"Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/136.0.0.0 Whale/4.32.315.22 Safari/537.36","ja3":"416eca07dcaad72dec6f76d1277b3eff","session":"cc962148-03ab-45f8-a7a7-8a9147ffd7ba","seq":1,"duration_ms":100,"bytes_in":275,"bytes_out":79},{"timestamp":"2026-08-20T21:18:10","port":80,"proto":"tcp","app_proto":"tls","app_protocol":"http","host":"<HONEYPOT>","headers":"{\"accept-encoding\":\"gzip\",\"host\":\"<HONEYPOT>:80\",\"user-agent\":\"Mozilla/5.0 (X11; Linux i686; rv:1.9.6.20) Gecko/ Firefox/3.8\"}","body":"","sni":"","tls_cipher":"TLS_AES_128_GCM_SHA256","tls_version":"TLSv1.3","alpn":[],"url_path":"/wp-content/plugins/import-xml-feed/readme.txt","summary":"","payload_hex":"474554202f77702d636f6e74656e742f706c7567696e732f696d706f72742d786d6c2d666565642f726561646d652e74787420485454502f312e310d0a486f73743a20<HONEYPOT>3a38300d0a557365722d4167656e743a204d6f7a696c6c612f352e3020285831313b204c696e757820693638363b2072763a312e392e362e323029204765636b6f2f2046697265666f782f332e380d0a4163636570742d456e636f64696e673a20677a69700d0a0d0a","method":"GET","user_agent":"Mozilla/5.0 (X11; Linux i686; rv:1.9.6.20) Gecko/ Firefox/3.8","ja3":"416eca07dcaad72dec6f76d1277b3eff","session":"30d6a97c-f63b-486f-afab-1b2a3500d621","seq":1,"duration_ms":101,"bytes_in":185,"bytes_out":79}],"http_methods":[{"method":"GET","count":772},{"method":"POST","count":656},{"method":"PUT","count":24}],"distinct_ports_total":33,"top_paths":[{"path":"/","count":104,"ports":7},{"path":"/wp-admin/admin-ajax.php","count":31,"ports":4},{"path":"/login","count":28,"ports":4},{"path":"/files/TUyIC5xf.php","count":24,"ports":4},{"path":"/_ping","count":20,"ports":20},{"path":"/solr/admin/cores?wt=json","count":16,"ports":4},{"path":"/apply_sec.cgi","count":12,"ports":4},{"path":"/__","count":12,"ports":4},{"path":"/module/","count":12,"ports":4},{"path":"/photo/p/api/album.php","count":11,"ports":4},{"path":"/login.php","count":10,"ports":4},{"path":"/rpc.cgi","count":8,"ports":4},{"path":"/wls-wsat/CoordinatorPortType","count":8,"ports":4},{"path":"/cgi-bin/DownloadCfg/RouterCfm.cfg","count":8,"ports":4},{"path":"/php/change_config.php","count":8,"ports":4}],"distinct_paths_total":200,"top_snis":[],"top_hosts":[{"value":"[::1]' UNION SELECT '/","count":4}],"top_alpns":[{"value":"http/1.1","count":1}],"banners":[{"value":"SSH-1337-OpenSSH_9.0","count":20}],"credentials":[{"username":"","password":"admin","count":8},{"username":"admin","password":"admin","count":7},{"username":"gsewb%20%26%20echo%20%cG9jLXRlc3Rpbmc%3D%22%20%7C%20base64%20-d%","password":"","count":6},{"username":";`cat /etc/passwd`","password":"\r\n","count":4},{"username":"YWRtaW4=","password":"YWRtaW4xMjM=","count":4},{"username":"Bki7yu')+OR+4191=LIKE('ABCDEFG',UPPER(HEX(RANDOMBLOB(50000000/2)","password":"pyUKnZH2","count":4},{"username":"root","password":"root","count":4},{"username":"","password":"axis2","count":4},{"username":"admin","password":"6b86b273ff34fce19d6b804eff5a3f5747ada4eaa22f1d49c01e52ddb7875b4b","count":4},{"username":"rootxx","password":"","count":4}],"header_profile":{"signature":["Accept","Accept-Encoding","Accept-Language","Content-Length","Content-Type","Host","User-Agent"],"representative":[{"name":"Accept","value":"*/*","notable":false},{"name":"Accept-Encoding","value":"gzip","notable":false},{"name":"Accept-Language","value":"en","notable":false},{"name":"Content-Length","value":"50","notable":false},{"name":"Content-Type","value":"application/json","notable":true},{"name":"Host","value":"<HONEYPOT>:9200","notable":false},{"name":"User-Agent","value":"Mozilla/5.0 (X11; Linux i686; rv:1.9.5.20) Gecko/ Firefox/3.6.4","notable":false}],"distinct_sets":5,"events_with_headers":10},"tags":[{"tag_id":"CVE-2017-1000486","tag_type":"cve","title":"Primetek Primefaces 5.x - Remote Code Execution","severity":"critical","actively_exploited":true,"match_field":"url_path","matched_pattern":"/javax.faces.resource/dynamiccontent.properties.xhtml","reference_urls":["https://github.com/mogwailabs/CVE-2017-1000486","https://github.com/pimps/CVE-2017-1000486","https://blog.mindedsecurity.com/2016/02/rce-in-oracle-netbeans-opensource.html","https://nvd.nist.gov/vuln/detail/CVE-2017-1000486","https://cryptosense.com/weak-encryption-flaw-in-primefaces/"]},{"tag_id":"CVE-2017-12149","tag_type":"cve","title":"Jboss Application Server - Remote Code Execution","severity":"critical","actively_exploited":true,"match_field":"url_path","matched_pattern":"/invoker/EJBInvokerServlet","reference_urls":["https://chowdera.com/2020/12/20201229190934023w.html","https://github.com/vulhub/vulhub/tree/master/jboss/CVE-2017-12149","https://nvd.nist.gov/vuln/detail/CVE-2017-12149","https://bugzilla.redhat.com/show_bug.cgi?id=1486220","https://access.redhat.com/errata/RHSA-2018:1607"]},{"tag_id":"CVE-2017-15944","tag_type":"cve","title":"Palo Alto Network PAN-OS - Remote Code Execution","severity":"critical","actively_exploited":true,"match_field":"url_path","matched_pattern":"/esp/cms_changeDeviceContext.esp?device=aaaaa:a%27\";user|s.\"1337\";","reference_urls":["https://www.exploit-db.com/exploits/43342","https://security.paloaltonetworks.com/CVE-2017-15944","http://blog.orange.tw/2019/07/attacking-ssl-vpn-part-1-preauth-rce-on-palo-alto.html","https://nvd.nist.gov/vuln/detail/CVE-2017-15944","http://www.securitytracker.com/id/1040007"]},{"tag_id":"CVE-2017-18362","tag_type":"cve","title":"Kaseya VSA 2017 ConnectWise ManagedITSync - Remote Code Execution","severity":"critical","actively_exploited":true,"match_field":"url_path","matched_pattern":"/KaseyaCwWebService/ManagedIT.asmx","reference_urls":["https://github.com/kbni/owlky","https://www.huntress.com/blog/cve-2017-18362-arbitrary-sql-injection-in-mangeditsync-integration-ba142ff24f4d"]},{"tag_id":"CVE-2017-9791","tag_type":"cve","title":"Apache Struts2 S2-053 - Remote Code Execution","severity":"critical","actively_exploited":true,"match_field":"url_path","matched_pattern":"/integration/saveGangster.action","reference_urls":["http://www.oracle.com/technetwork/security-advisory/alert-cve-2017-9805-3889403.html","http://struts.apache.org/docs/s2-048.html","http://web.archive.org/web/20211207175819/https://securitytracker.com/id/1038838","http://www.securitytracker.com/id/1038838","https://security.netapp.com/advisory/ntap-20180706-0002/"]},{"tag_id":"CVE-2018-15961","tag_type":"cve","title":"Adobe ColdFusion - Unrestricted File Upload Remote Code Execution","severity":"critical","actively_exploited":true,"match_field":"url_path","matched_pattern":"/cf_scripts/scripts/ajax/ckeditor/plugins/filemanager/upload.cfm","reference_urls":["https://nvd.nist.gov/vuln/detail/CVE-2018-15961","https://github.com/xbufu/CVE-2018-15961","https://helpx.adobe.com/security/products/coldfusion/apsb18-33.html","http://web.archive.org/web/20220309060906/http://www.securitytracker.com/id/1041621","http://www.securitytracker.com/id/1041621"]},{"tag_id":"CVE-2018-6961","tag_type":"cve","title":"VMware NSX SD-WAN Edge - Command Injection","severity":"critical","actively_exploited":true,"match_field":"url_path","matched_pattern":"/scripts/ajaxPortal.lua","reference_urls":["https://www.vmware.com/security/advisories/VMSA-2018-0011.html","https://www.exploit-db.com/exploits/44959","https://nvd.nist.gov/vuln/detail/CVE-2018-6961"]},{"tag_id":"CVE-2018-7600","tag_type":"cve","title":"Drupal - Remote Code Execution","severity":"critical","actively_exploited":true,"match_field":"url_path","matched_pattern":"/user/register","reference_urls":["https://github.com/vulhub/vulhub/tree/master/drupal/CVE-2018-7600","https://nvd.nist.gov/vuln/detail/CVE-2018-7600","https://www.drupal.org/sa-core-2018-002","https://groups.drupal.org/security/faq-2018-002","http://www.securitytracker.com/id/1040598"]},{"tag_id":"CVE-2019-10068","tag_type":"cve","title":"Kentico CMS Insecure Deserialization Remote Code Execution","severity":"critical","actively_exploited":true,"match_field":"url_path","matched_pattern":"/CMSPages/Staging/SyncServer.asmx/ProcessSynchronizationTaskData","reference_urls":["https://www.aon.com/cyber-solutions/aon_cyber_labs/unauthenticated-remote-code-execution-in-kentico-cms/","https://packetstormsecurity.com/files/157588/Kentico-CMS-12.0.14-Remote-Command-Execution.html","https://nvd.nist.gov/vuln/detail/CVE-2019-10068","https://github.com/rapid7/metasploit-framework/pull/13107","http://packetstormsecurity.com/files/157588/Kentico-CMS-12.0.14-Remote-Command-Execution.html"]},{"tag_id":"CVE-2019-11580","tag_type":"cve","title":"Atlassian Crowd and Crowd Data Center - Unauthenticated Remote Code Execution","severity":"critical","actively_exploited":true,"match_field":"url_path","matched_pattern":"/crowd/admin/uploadplugin.action","reference_urls":["https://github.com/jas502n/CVE-2019-11580","https://jira.atlassian.com/browse/CWD-5388","https://nvd.nist.gov/vuln/detail/CVE-2019-11580","http://packetstormsecurity.com/files/163810/Atlassian-Crowd-pdkinstall-Remote-Code-Execution.html","https://github.com/Elsfa7-110/kenzer-templates"]},{"tag_id":"CVE-2019-12989","tag_type":"cve","title":"Citrix SD-WAN and NetScaler SD-WAN - SQL Injection","severity":"critical","actively_exploited":true,"match_field":"url_path","matched_pattern":"/sdwan/nitro/v1/config/get_package_file","reference_urls":["http://packetstormsecurity.com/files/153638/Citrix-SD-WAN-Appliance-10.2.2-Authentication-Bypass-Remote-Command-Execution.html","https://support.citrix.com/article/CTX251987","https://www.tenable.com/security/research/tra-2019-32","https://nvd.nist.gov/vuln/detail/CVE-2019-12989"]},{"tag_id":"CVE-2019-16278","tag_type":"cve","title":"nostromo 1.9.6 - Remote Code Execution","severity":"critical","actively_exploited":true,"match_field":"url_path","matched_pattern":"/.%0d./.%0d./.%0d./.%0d./bin/sh","reference_urls":["https://packetstormsecurity.com/files/155802/nostromo-1.9.6-Remote-Code-Execution.html","https://www.exploit-db.com/raw/47837","https://nvd.nist.gov/vuln/detail/CVE-2019-16278","http://www.nazgul.ch/dev/nostromo_cl.txt","http://packetstormsecurity.com/files/155045/Nostromo-1.9.6-Directory-Traversal-Remote-Command-Execution.html"]},{"tag_id":"CVE-2019-3396","tag_type":"cve","title":"Atlassian Confluence Server - Path Traversal","severity":"critical","actively_exploited":true,"match_field":"url_path","matched_pattern":"/rest/tinymce/1/macro/preview","reference_urls":["https://github.com/x-f1v3/CVE-2019-3396","https://nvd.nist.gov/vuln/detail/CVE-2019-3396","https://jira.atlassian.com/browse/CONFSERVER-57974","http://packetstormsecurity.com/files/152568/Atlassian-Confluence-Widget-Connector-Macro-Velocity-Template-Injection.html","https://github.com/ARPSyndicate/cvemon"]},{"tag_id":"CVE-2019-7609","tag_type":"cve","title":"Kibana Timelion - Arbitrary Code Execution","severity":"critical","actively_exploited":true,"match_field":"url_path","matched_pattern":"/api/timelion/run","reference_urls":["https://github.com/mpgn/CVE-2019-7609","https://discuss.elastic.co/t/elastic-stack-6-6-1-and-5-6-15-security-update/169077","https://nvd.nist.gov/vuln/detail/CVE-2019-7609","https://www.elastic.co/community/security","https://access.redhat.com/errata/RHBA-2019:2824"]},{"tag_id":"CVE-2019-9670","tag_type":"cve","title":"Synacor Zimbra Collaboration <8.7.11p10 - XML External Entity Injection","severity":"critical","actively_exploited":true,"match_field":"url_path","matched_pattern":"/Autodiscover/Autodiscover.xml","reference_urls":["https://www.exploit-db.com/exploits/46693/","https://wiki.zimbra.com/wiki/Zimbra_Security_Advisories","https://bugzilla.zimbra.com/show_bug.cgi?id=109129","http://www.rapid7.com/db/modules/exploit/linux/http/zimbra_xxe_rce","http://packetstormsecurity.com/files/152487/Zimbra-Collaboration-Autodiscover-Servlet-XXE-ProxyServlet-SSRF.html"]},{"tag_id":"CVE-2020-12641","tag_type":"cve","title":"Roundcube Webmail - Command Injection","severity":"critical","actively_exploited":true,"match_field":"url_path","matched_pattern":"/installer/index.php","reference_urls":["https://nvd.nist.gov/vuln/detail/CVE-2020-12641","https://github.com/mbadanoiu/CVE-2020-12641","http://lists.opensuse.org/opensuse-security-announce/2020-09/msg00083.html","https://github.com/roundcube/roundcubemail/compare/1.4.3...1.4.4","https://github.com/roundcube/roundcubemail/releases/tag/1.4.4"]},{"tag_id":"CVE-2020-15415","tag_type":"cve","title":"DrayTek Vigor - Command Injection","severity":"critical","actively_exploited":true,"match_field":"url_path","matched_pattern":"/cgi-bin/mainfunction.cgi/cvmcfgupload","reference_urls":["https://github.com/CLP-team/Vigor-Commond-Injection","https://nvd.nist.gov/vuln/detail/CVE-2020-15415"]},{"tag_id":"CVE-2020-15505","tag_type":"cve","title":"MobileIron Core & Connector <= v10.6 & Sentry <= v9.8 - Remote Code Execution","severity":"critical","actively_exploited":true,"match_field":"url_path","matched_pattern":"/mifs/.;/services/LogService","reference_urls":["https://blog.orange.tw/2020/09/how-i-hacked-facebook-again-mobileiron-mdm-rce.html","https://github.com/iamnoooob/CVE-Reverse/tree/master/CVE-2020-15505","https://github.com/iamnoooob/CVE-Reverse/blob/master/CVE-2020-15505/hessian.py#L10","https://github.com/orangetw/JNDI-Injection-Bypass","https://nvd.nist.gov/vuln/detail/CVE-2020-15505"]},{"tag_id":"CVE-2020-25213","tag_type":"cve","title":"WordPress File Manager Plugin - Remote Code Execution","severity":"critical","actively_exploited":true,"match_field":"url_path","matched_pattern":"/wp-content/plugins/wp-file-manager/lib/php/connector.minimal.php","reference_urls":["https://plugins.trac.wordpress.org/changeset/2373068","https://github.com/w4fz5uck5/wp-file-manager-0day","https://nvd.nist.gov/vuln/detail/CVE-2020-25213","http://packetstormsecurity.com/files/160003/WordPress-File-Manager-6.8-Remote-Code-Execution.html","http://packetstormsecurity.com/files/171650/WordPress-File-Manager-6.9-Shell-Upload.html"]},{"tag_id":"CVE-2020-8515","tag_type":"cve","title":"DrayTek - Remote Code Execution","severity":"critical","actively_exploited":true,"match_field":"url_path","matched_pattern":"/cgi-bin/mainfunction.cgi","reference_urls":["https://www.draytek.com/about/security-advisory/vigor3900-/-vigor2960-/-vigor300b-router-web-management-page-vulnerability-(cve-2020-8515)","https://blog.netlab.360.com/two-zero-days-are-targeting-draytek-broadband-cpe-devices-en/","https://nvd.nist.gov/vuln/detail/CVE-2020-8515","https://sku11army.blogspot.com/2020/01/draytek-unauthenticated-rce-in-draytek.html","https://www.draytek.com/about/security-advisory/vigor3900-/-vigor2960-/-vigor300b-router-web-management-page-vulnerability-%28cve-2020-8515%29/"]},{"tag_id":"CVE-2017-12615","tag_type":"cve","title":"Apache Tomcat Servers - Remote Code Execution","severity":"high","actively_exploited":true,"match_field":"url_path","matched_pattern":"/poc.jsp?cmd=cat+%2Fetc%2Fpasswd","reference_urls":["https://github.com/vulhub/vulhub/tree/master/tomcat/CVE-2017-12615","https://lists.apache.org/thread.html/8fcb1e2d5895413abcf266f011b9918ae03e0b7daceb118ffbf23f8c@%3Cannounce.tomcat.apache.org%3E","http://web.archive.org/web/20211206035549/https://securitytracker.com/id/1039392","https://nvd.nist.gov/vuln/detail/CVE-2017-12615","http://breaktoprotect.blogspot.com/2017/09/the-case-of-cve-2017-12615-tomcat-7-put.html"]},{"tag_id":"CVE-2019-9082","tag_type":"cve","title":"ThinkPHP < 3.2.4 - Remote Code Execution","severity":"high","actively_exploited":true,"match_field":"url_path","matched_pattern":"/index.php?s=/Index/\\think\\app/invokefunction&function=call_user_func_array&vars[0]=system&vars[1][]=echo%20thinkphp%20%","reference_urls":["https://github.com/xyl-tools/open_source_bms/issues/33","http://packetstormsecurity.com/files/157218/ThinkPHP-5.0.23-Remote-Code-Execution.html","https://www.exploit-db.com/exploits/46488/","https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/unix/webapp/thinkphp_rce.rb","https://nvd.nist.gov/vuln/detail/CVE-2019-9082"]},{"tag_id":"CVE-2019-9621","tag_type":"cve","title":"Zimbra Collaboration Suite - SSRF","severity":"high","actively_exploited":true,"match_field":"url_path","matched_pattern":"/autodiscover","reference_urls":["https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/linux/http/zimbra_xxe_rce.rb","https://nvd.nist.gov/vuln/detail/cve-2019-9621","http://packetstormsecurity.com/files/153190/Zimbra-XML-Injection-Server-Side-Request-Forgery.html","https://blog.tint0.com/2019/03/a-saga-of-code-executions-on-zimbra.html","https://bugzilla.zimbra.com/show_bug.cgi?id=109127"]},{"tag_id":"CVE-2020-10199","tag_type":"cve","title":"Sonatype Nexus Repository Manager 3 - Remote Code Execution","severity":"high","actively_exploited":true,"match_field":"url_path","matched_pattern":"/service/rest/beta/repositories/bower/group","reference_urls":["https://twitter.com/iamnoooob/status/1246182773427240967","https://securitylab.github.com/advisories/GHSL-2020-011-nxrm-sonatype","https://nvd.nist.gov/vuln/detail/CVE-2020-10199","http://packetstormsecurity.com/files/157261/Nexus-Repository-Manager-3.21.1-01-Remote-Code-Execution.html","https://cwe.mitre.org/data/definitions/917.html"]},{"tag_id":"CVE-2020-11978","tag_type":"cve","title":"Apache Airflow <=1.10.10 - Remote Code Execution","severity":"high","actively_exploited":true,"match_field":"url_path","matched_pattern":"/api/experimental/dags/example_trigger_target_dag/dag_runs","reference_urls":["https://github.com/pberba/CVE-2020-11978","https://twitter.com/wugeej/status/1400336603604668418","https://lists.apache.org/thread.html/r7255cf0be3566f23a768e2a04b40fb09e52fcd1872695428ba9afe91%40%3Cusers.airflow.apache.org%3E","https://nvd.nist.gov/vuln/detail/CVE-2020-11978","http://packetstormsecurity.com/files/174764/Apache-Airflow-1.10.10-Remote-Code-Execution.html"]},{"tag_id":"CVE-2020-14883","tag_type":"cve","title":"Oracle Fusion Middleware WebLogic Server Administration Console - Remote Code Execution","severity":"high","actively_exploited":true,"match_field":"url_path","matched_pattern":"/console/images/%252e%252e%252fconsole.portal","reference_urls":["https://packetstormsecurity.com/files/160143/Oracle-WebLogic-Server-Administration-Console-Handle-Remote-Code-Execution.html","https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-14883","https://www.oracle.com/security-alerts/cpuoct2020.html","http://packetstormsecurity.com/files/160143/Oracle-WebLogic-Server-Administration-Console-Handle-Remote-Code-Execution.html","https://github.com/1n7erface/PocList"]},{"tag_id":"CVE-2020-1956","tag_type":"cve","title":"Apache Kylin 3.0.1 - Command Injection Vulnerability","severity":"high","actively_exploited":true,"match_field":"url_path","matched_pattern":"/kylin/api/user/authentication","reference_urls":["https://www.sonarsource.com/blog/apache-kylin-command-injection-vulnerability/","https://community.sonarsource.com/t/apache-kylin-3-0-1-command-injection-vulnerability/25706","https://nvd.nist.gov/vuln/detail/CVE-2020-1956","http://www.openwall.com/lists/oss-security/2020/07/14/1","https://lists.apache.org/thread.html/r021baf9d8d4ae41e8c8332c167c4fa96c91b5086563d9be55d2d7acf@%3Ccommits.kylin.apache.org%3E"]},{"tag_id":"CVE-2010-0219","tag_type":"cve","title":"Apache Axis2 Default Login","severity":"critical","actively_exploited":false,"match_field":"url_path","matched_pattern":"/axis2-admin/login","reference_urls":["https://nvd.nist.gov/vuln/detail/CVE-2010-0219","https://knowledge.broadcom.com/external/article/13994/vulnerability-axis2-default-administrato.html","http://www.rapid7.com/security-center/advisories/R7-0037.jsp","http://www.vupen.com/english/advisories/2010/2673","http://retrogod.altervista.org/9sg_ca_d2d.html"]},{"tag_id":"CVE-2014-9614","tag_type":"cve","title":"Netsweeper 4.0.5 - Default Weak Account","severity":"critical","actively_exploited":false,"match_field":"url_path","matched_pattern":"/webadmin/auth/verification.php","reference_urls":["https://packetstormsecurity.com/files/download/133034/netsweeper-issues.tgz","https://nvd.nist.gov/vuln/detail/CVE-2014-9614","http://packetstormsecurity.com/files/133034/Netsweeper-Bypass-XSS-Redirection-SQL-Injection-Execution.html","https://github.com/ARPSyndicate/kenzer-templates"]},{"tag_id":"CVE-2016-15042","tag_type":"cve","title":"WordPress Frontend File Manager < 4.0 & N-Media Post Frontend < 1.1 - Arbitrary File Upload","severity":"critical","actively_exploited":false,"match_field":"url_path","matched_pattern":"/wp-content/uploads/post_files","reference_urls":["https://www.pluginvulnerabilities.com/2016/09/19/arbitrary-file-upload-vulnerability-in-front-end-file-upload-and-manager-plugin/","https://www.pluginvulnerabilities.com/2016/09/19/arbitrary-file-upload-vulnerability-in-n-media-post-front-end-form/","https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-15042","https://wordpress.org/plugins/nmedia-user-file-uploader/#developers","https://wpscan.com/vulnerability/052f7d9a-aaff-4fb1-92b7-aeb83cc705a7"]},{"tag_id":"CVE-2016-5649","tag_type":"cve","title":"NETGEAR DGN2200 / DGND3700 - Admin Password Disclosure","severity":"critical","actively_exploited":false,"match_field":"url_path","matched_pattern":"/BSW_cxttongr.htm","reference_urls":["https://nvd.nist.gov/vuln/detail/CVE-2016-5649","https://packetstormsecurity.com/files/140342/Netgear-DGN2200-DGND3700-WNDR4500-Information-Disclosure.html","http://packetstormsecurity.com/files/152675/Netgear-DGN2200-DGND3700-Admin-Password-Disclosure.html","https://github.com/ARPSyndicate/cvemon","https://github.com/ARPSyndicate/kenzer-templates"]},{"tag_id":"CVE-2017-12635","tag_type":"cve","title":"Apache CouchDB 1.7.0 / 2.x < 2.1.1 - Remote Privilege Escalation","severity":"critical","actively_exploited":false,"match_field":"url_path","matched_pattern":"/_users/org.couchdb.user:poc","reference_urls":["https://nvd.nist.gov/vuln/detail/CVE-2017-12635","https://lists.apache.org/thread.html/6c405bf3f8358e6314076be9f48c89a2e0ddf00539906291ebdf0c67@%3Cdev.couchdb.apache.org%3E","https://security.gentoo.org/glsa/201711-16","https://lists.debian.org/debian-lts-announce/2018/01/msg00026.html","https://support.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbmu03935en_us"]},{"tag_id":"CVE-2017-5983","tag_type":"cve","title":"JIRA Workflow Designer Plugin in Atlassian JIRA Server > 6.3.0 - Remote Code Execution (XXE)","severity":"critical","actively_exploited":false,"match_field":"url_path","matched_pattern":"/jira/secure/Dashboard.jspa","reference_urls":["https://nvd.nist.gov/vuln/detail/CVE-2017-5983","https://code-white.com/blog/2017-04-amf/"]},{"tag_id":"CVE-2018-11686","tag_type":"cve","title":"FlexPaper/FlowPaper 2.3.6 - Remote Code Execution","severity":"critical","actively_exploited":false,"match_field":"url_path","matched_pattern":"/php/config/output.txt","reference_urls":["https://nvd.nist.gov/vuln/detail/CVE-2018-11686"]},{"tag_id":"CVE-2018-1217","tag_type":"cve","title":"Dell EMC Avamar and Integrated Data Protection Appliance Installation Manager - Invalid Access Control","severity":"critical","actively_exploited":false,"match_field":"url_path","matched_pattern":"/avi/avigui/avigwt","reference_urls":["https://www.exploit-db.com/exploits/44441","https://nvd.nist.gov/vuln/detail/CVE-2018-1217"]},{"tag_id":"CVE-2018-14728","tag_type":"cve","title":"Responsive filemanager 9.13.1 Server-Side Request Forgery","severity":"critical","actively_exploited":false,"match_field":"url_path","matched_pattern":"/filemanager/upload.php","reference_urls":["http://packetstormsecurity.com/files/148742/Responsive-Filemanager-9.13.1-Server-Side-Request-Forgery.html","https://www.exploit-db.com/exploits/45103/","https://nvd.nist.gov/vuln/detail/CVE-2018-14728","https://github.com/sobinge/nuclei-templates","https://github.com/ARPSyndicate/kenzer-templates"]},{"tag_id":"CVE-2018-17153","tag_type":"cve","title":"Western Digital MyCloud NAS - Authentication Bypass","severity":"critical","actively_exploited":false,"match_field":"url_path","matched_pattern":"/web/google_analytics.php","reference_urls":["https://web.archive.org/web/20170315123948/https://www.stevencampbell.info/2016/12/command-injection-in-western-digital-mycloud-nas/","https://packetstormsecurity.com/files/173802/Western-Digital-MyCloud-Unauthenticated-Command-Injection.html","https://securify.nl/nl/advisory/SFY20180102/authentication-bypass-vulnerability-in-western-digital-my-cloud-allows-escalation-to-admin-privileges.html","https://nvd.nist.gov/vuln/detail/CVE-2016-10108","http://packetstormsecurity.com/files/173802/Western-Digital-MyCloud-Unauthenticated-Command-Injection.html"]},{"tag_id":"CVE-2018-17207","tag_type":"cve","title":"WordPress Duplicator Plugin < 1.2.42 - Arbitrary Code Execution","severity":"critical","actively_exploited":false,"match_field":"url_path","matched_pattern":"/installer-backup.php","reference_urls":["https://www.synacktiv.com/posts/exploit/wordpress-duplicator-plugin-arbitrary-code-execution.html","https://nvd.nist.gov/vuln/detail/CVE-2018-17207"]},{"tag_id":"CVE-2018-17431","tag_type":"cve","title":"Comodo Unified Threat Management Web Console - Remote Code Execution","severity":"critical","actively_exploited":false,"match_field":"url_path","matched_pattern":"/manage/webshell/u?s=5&w=218&h=15&k=%0a&l=62&_=5621298674064","reference_urls":["https://www.exploit-db.com/exploits/48825","https://secure.comodo.com/home/purchase.php?pid=106&license=try&track=9276&af=9276","https://nvd.nist.gov/vuln/detail/CVE-2018-17431","https://github.com/Fadavvi/CVE-2018-17431-PoC#confirmation-than-bug-exist-2018-09-25-ticket-id-xwr-503-79437","https://drive.google.com/file/d/0BzFJhNQNHcoTbndsUmNjVWNGYWNJaWxYcWNyS2ZDajluTDFz/view"]},{"tag_id":"CVE-2018-19127","tag_type":"cve","title":"PHPCMS 2008 - Remote Code Execution via Template Injection","severity":"critical","actively_exploited":false,"match_field":"url_path","matched_pattern":"/data/cache_template/rss.tpl.php","reference_urls":["https://github.com/ab1gale/phpcms-2008-CVE-2018-19127","https://github.com/advisories/GHSA-p498-q357-m3p7","https://nvd.nist.gov/vuln/detail/CVE-2018-19127"]},{"tag_id":"CVE-2018-20526","tag_type":"cve","title":"Roxy Fileman 1.4.5 - Unrestricted File Upload","severity":"critical","actively_exploited":false,"match_field":"url_path","matched_pattern":"/php/upload.php","reference_urls":["http://packetstormsecurity.com/files/151033/Roxy-Fileman-1.4.5-File-Upload-Directory-Traversal.html","https://www.exploit-db.com/exploits/46085/","https://nvd.nist.gov/vuln/detail/CVE-2018-20526","https://github.com/ARPSyndicate/cvemon","https://github.com/ARPSyndicate/kenzer-templates"]},{"tag_id":"CVE-2018-20985","tag_type":"cve","title":"WordPress Payeezy Pay <=2.97 - Local File Inclusion","severity":"critical","actively_exploited":false,"match_field":"url_path","matched_pattern":"/wp-content/plugins/wp-payeezy-pay/donate.php","reference_urls":["https://www.pluginvulnerabilities.com/2018/12/06/our-improved-proactive-monitoring-has-now-caught-a-local-file-inclusion-lfi-vulnerability-as-well/","https://wordpress.org/plugins/wp-payeezy-pay/#developers","https://nvd.nist.gov/vuln/detail/CVE-2018-20985","https://github.com/ARPSyndicate/kenzer-templates","https://github.com/ARPSyndicate/cvemon"]},{"tag_id":"CVE-2018-25114","tag_type":"cve","title":"osCommerce 2.3.4.1 - Remote Code Execution","severity":"critical","actively_exploited":false,"match_field":"url_path","matched_pattern":"/install/includes/configure.php","reference_urls":["https://www.exploit-db.com/exploits/50128","https://github.com/nobodyatall648/osCommerce-2.3.4-Remote-Command-Execution","https://www.exploit-db.com/exploits/44374","https://www.vulncheck.com/advisories/oscommerce-installer-unauth-config-file-injection-php-code-execution"]},{"tag_id":"CVE-2018-2894","tag_type":"cve","title":"Oracle WebLogic Server - Remote Code Execution","severity":"critical","actively_exploited":false,"match_field":"url_path","matched_pattern":"/ws_utc/resources/setting/keystore","reference_urls":["https://blog.detectify.com/2018/11/14/technical-explanation-of-cve-2018-2894-oracle-weblogic-rce/","https://github.com/vulhub/vulhub/tree/fda47b97c7d2809660a4471539cd0e6dbf8fac8c/weblogic/CVE-2018-2894","https://nvd.nist.gov/vuln/detail/CVE-2018-2894","http://www.oracle.com/technetwork/security-advisory/cpujul2018-4258247.html","http://www.securitytracker.com/id/1041301"]},{"tag_id":"CVE-2019-12990","tag_type":"cve","title":"Citrix SD-WAN Center - Local File Inclusion","severity":"critical","actively_exploited":false,"match_field":"url_path","matched_pattern":"/Collector/appliancesettings/applianceSettingsFileTransfer","reference_urls":["https://www.tenable.com/security/research/tra-2019-31","https://support.citrix.com/search?searchQuery=*&lang=en&sort=relevance&prod=&pver=&ct=Security+Bulletin","https://nvd.nist.gov/vuln/detail/CVE-2019-12990","https://support.citrix.com/search?searchQuery=%2A&lang=en&sort=relevance&prod=&pver=&ct=Security+Bulletin"]},{"tag_id":"CVE-2019-13372","tag_type":"cve","title":"D-Link Central WiFi Manager CWM(100) - Remote Code Execution","severity":"critical","actively_exploited":false,"match_field":"url_path","matched_pattern":"/index.php/Index/index","reference_urls":["https://github.com/unh3x/unh3x.github.io/blob/master/_posts/2019-02-21-D-link-%28CWM-100%29-Multiple-Vulnerabilities.md","https://supportannouncement.us.dlink.com/announcement/publication.aspx?name=SAP10117","https://unh3x.github.io/2019/02/21/D-link-%28CWM-100%29-Multiple-Vulnerabilities/","https://nvd.nist.gov/vuln/detail/CVE-2019-13372"]},{"tag_id":"CVE-2019-17444","tag_type":"cve","title":"Jfrog Artifactory <6.17.0 - Default Admin Password","severity":"critical","actively_exploited":false,"match_field":"url_path","matched_pattern":"/ui/auth/login","reference_urls":["https://www.jfrog.com/confluence/display/JFROG/Artifactory+Release+Notes","https://www.jfrog.com/confluence/display/JFROG/JFrog+Artifactory","https://nvd.nist.gov/vuln/detail/CVE-2019-17444","https://github.com/ARPSyndicate/kenzer-templates"]},{"tag_id":"CVE-2019-1821","tag_type":"cve","title":"Cisco Prime Infrastructure and Cisco Evolved Programmable Network Manager - Remote Code Execution","severity":"critical","actively_exploited":false,"match_field":"url_path","matched_pattern":"/servlet/UploadServlet","reference_urls":["https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20190515-pi-rce","https://srcincite.io/blog/2019/05/17/panic-at-the-cisco-unauthenticated-rce-in-prime-infrastructure.html","https://nvd.nist.gov/vuln/detail/CVE-2019-1821","http://packetstormsecurity.com/files/153350/Cisco-Prime-Infrastructure-Health-Monitor-TarArchive-Directory-Traversal.html","https://github.com/ARPSyndicate/kenzer-templates"]},{"tag_id":"CVE-2019-18818","tag_type":"cve","title":"strapi CMS <3.0.0-beta.17.5 - Admin Password Reset","severity":"critical","actively_exploited":false,"match_field":"url_path","matched_pattern":"/admin/auth/reset-password","reference_urls":["https://github.com/advisories/GHSA-6xc2-mj39-q599","https://www.exploit-db.com/exploits/50239","https://nvd.nist.gov/vuln/detail/CVE-2019-18818","https://github.com/strapi/strapi/releases/tag/v3.0.0-beta.17.5","https://github.com/strapi/strapi/pull/4443"]},{"tag_id":"CVE-2019-2729","tag_type":"cve","title":"Oracle WebLogic Server Administration Console - Remote Code Execution","severity":"critical","actively_exploited":false,"match_field":"url_path","matched_pattern":"/_async/favicon.ico","reference_urls":["https://www.oracle.com/security-alerts/alert-cve-2019-2729.html","https://nvd.nist.gov/vuln/detail/CVE-2019-2729","http://www.oracle.com/technetwork/security-advisory/alert-cve-2019-2729-5570780.html","http://www.oracle.com/technetwork/security-advisory/cpujul2019-5072835.html","https://www.oracle.com/security-alerts/cpuapr2020.html"]},{"tag_id":"CVE-2019-5127","tag_type":"cve","title":"YouPHPTube Encoder 2.3 - Remote Command Injection","severity":"critical","actively_exploited":false,"match_field":"url_path","matched_pattern":"/objects/getImage.php","reference_urls":["https://talosintelligence.com/vulnerability_reports/TALOS-2019-0917","https://nvd.nist.gov/vuln/detail/CVE-2019-5127","https://github.com/ARPSyndicate/kenzer-templates","https://github.com/Elsfa7-110/kenzer-templates","https://github.com/sobinge/nuclei-templates"]},{"tag_id":"CVE-2019-5434","tag_type":"cve","title":"Revive Adserver 4.2 - Remote Code Execution","severity":"critical","actively_exploited":false,"match_field":"url_path","matched_pattern":"/adxmlrpc.php","reference_urls":["https://packetstormsecurity.com/files/155559/Revive-Adserver-4.2-Remote-Code-Execution.html","https://www.exploit-db.com/exploits/47739","https://www.revive-adserver.com/security/revive-sa-2019-001/","https://nvd.nist.gov/vuln/detail/CVE-2019-5434","http://packetstormsecurity.com/files/155559/Revive-Adserver-4.2-Remote-Code-Execution.html"]},{"tag_id":"CVE-2019-7276","tag_type":"cve","title":"Optergy Proton/Enterprise - Unauthenticated RCE via Backdoor Console","severity":"critical","actively_exploited":false,"match_field":"url_path","matched_pattern":"/tools/ajax/ConsoleResult.html","reference_urls":["https://nvd.nist.gov/vuln/detail/CVE-2019-7276","https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/linux/http/optergy_bms_backdoor_rce_cve_2019_7276.rb","https://attackerkb.com/topics/QrYFIjnd3J/cve-2019-7276","https://www.zeroscience.mk/files/ioybms_gk_2019.pdf"]},{"tag_id":"CVE-2019-9733","tag_type":"cve","title":"JFrog Artifactory 6.7.3 - Admin Login Bypass","severity":"critical","actively_exploited":false,"match_field":"url_path","matched_pattern":"/artifactory/ui/auth/login","reference_urls":["http://packetstormsecurity.com/files/152172/JFrog-Artifactory-Administrator-Authentication-Bypass.html","https://www.ciphertechs.com/jfrog-artifactory-advisory/","https://www.jfrog.com/confluence/display/RTF/Release+Notes#ReleaseNotes-Artifactory6.8.6","https://nvd.nist.gov/vuln/detail/CVE-2019-9733","https://github.com/ARPSyndicate/kenzer-templates"]},{"tag_id":"CVE-2020-11546","tag_type":"cve","title":"SuperWebmailer 7.21.0.01526 - Remote Code Execution","severity":"critical","actively_exploited":false,"match_field":"url_path","matched_pattern":"/mailingupgrade.php","reference_urls":["https://github.com/Official-BlackHat13/CVE-2020-11546/","https://blog.to.com/advisory-superwebmailer-cve-2020-11546/","https://nvd.nist.gov/vuln/detail/CVE-2020-11546","https://github.com/ARPSyndicate/kenzer-templates","https://github.com/HimmelAward/Goby_POC"]},{"tag_id":"CVE-2020-13167","tag_type":"cve","title":"Netsweeper <=6.4.3 - Python Code Injection","severity":"critical","actively_exploited":false,"match_field":"url_path","matched_pattern":"/webadmin/out","reference_urls":["https://ssd-disclosure.com/ssd-advisory-netsweeper-preauth-rce/","https://portswigger.net/daily-swig/severe-rce-vulnerability-in-content-filtering-system-has-been-patched-netsweeper-says","https://nvd.nist.gov/vuln/detail/CVE-2020-13167","https://github.com/ARPSyndicate/kenzer-templates","https://github.com/Elsfa7-110/kenzer-templates"]},{"tag_id":"CVE-2020-35729","tag_type":"cve","title":"Klog Server <=2.41 - Unauthenticated Command Injection","severity":"critical","actively_exploited":false,"match_field":"url_path","matched_pattern":"/actions/authenticate.php","reference_urls":["https://docs.unsafe-inline.com/0day/klog-server-unauthentication-command-injection","https://nvd.nist.gov/vuln/detail/CVE-2020-35729","https://github.com/mustgundogdu/Research/blob/main/KLOG_SERVER/Exploit_Code","https://github.com/mustgundogdu/Research/blob/main/KLOG_SERVER/README.md","https://github.com/Z0fhack/Goby_POC"]},{"tag_id":"CVE-2024-51568","tag_type":"cve","title":"CyberPanel - Command Injection","severity":"critical","actively_exploited":false,"match_field":"url_path","matched_pattern":"/filemanager/upload","reference_urls":["https://www.rapid7.com/db/modules/exploit/unix/webapp/cyberpanel_preauth_rce_multi_cve/","https://dreyand.rs/code/review/2024/10/27/what-are-my-options-cyberpanel-v236-pre-auth-rce","https://nvd.nist.gov/vuln/detail/CVE-2024-51568","https://cyberpanel.net/blog/cyberpanel-v2-3-5"]},{"tag_id":"CVE-2026-5718","tag_type":"cve","title":"Drag and Drop Multiple File Upload - CF7 <= 1.3.9.6 - Remote Code Execution","severity":"critical","actively_exploited":false,"match_field":"url_path","matched_pattern":"/wp-content/uploads/wp_dndcf7_uploads","reference_urls":["https://nvd.nist.gov/vuln/detail/CVE-2026-5718","https://wordpress.org/plugins/drag-and-drop-multiple-file-upload-contact-form-7/"]},{"tag_id":"CVE-2015-7245","tag_type":"cve","title":"D-Link DVG-N5402SP - Local File Inclusion","severity":"high","actively_exploited":false,"match_field":"url_path","matched_pattern":"/cgibin/webproc","reference_urls":["https://packetstormsecurity.com/files/135590/D-Link-DVG-N5402SP-Path-Traversal-Information-Disclosure.html","https://www.exploit-db.com/exploits/39409/","https://nvd.nist.gov/vuln/detail/CVE-2015-7245","https://github.com/ARPSyndicate/cvemon","https://github.com/ARPSyndicate/kenzer-templates"]},{"tag_id":"CVE-2016-10960","tag_type":"cve","title":"WordPress wSecure Lite < 2.4 - Remote Code Execution","severity":"high","actively_exploited":false,"match_field":"url_path","matched_pattern":"/wp-content/plugins/wsecure/wsecure-config.php","reference_urls":["https://www.pluginvulnerabilities.com/2016/07/12/remote-code-execution-rce-vulnerability-in-wsecure-lite/","https://www.acunetix.com/vulnerabilities/web/wordpress-plugin-wsecure-lite-remote-code-execution-2-3/","https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-10960","https://wordpress.org/plugins/wsecure/#developers","https://github.com/ARPSyndicate/cvemon"]},{"tag_id":"CVE-2016-3081","tag_type":"cve","title":"Apache S2-032 Struts - Remote Code Execution","severity":"high","actively_exploited":false,"match_field":"url_path","matched_pattern":"/index.action?method:%23_memberAccess%3d@ognl.OgnlContext@DEFAULT_MEMBER_ACCESS,%23res%3d%40org.apache.struts2.ServletAc","reference_urls":["https://cwiki.apache.org/confluence/display/WW/S2-032","https://struts.apache.org/docs/s2-032.html","https://nvd.nist.gov/vuln/detail/CVE-2016-3081","http://web.archive.org/web/20211207042547/https://securitytracker.com/id/1035665","http://www.huawei.com/en/psirt/security-advisories/huawei-sa-20160527-01-struts2-en"]},{"tag_id":"CVE-2017-17762","tag_type":"cve","title":"Episerver 7 - Blind XML External Entity Injection","severity":"high","actively_exploited":false,"match_field":"url_path","matched_pattern":"/util/xmlrpc/Handler.ashx","reference_urls":["https://gist.github.com/jonaslejon/5f92779848360a1a1e676af0795bd9aa","https://kryptera.se/sarbarhet-i-episerver/","https://github.com/ARPSyndicate/cvemon"]},{"tag_id":"CVE-2018-1000130","tag_type":"cve","title":"Jolokia Agent - JNDI Code Injection","severity":"high","actively_exploited":false,"match_field":"url_path","matched_pattern":"/jolokia/read/getDiagnosticOptions","reference_urls":["https://jolokia.org/#Security_fixes_with_1.5.0","https://access.redhat.com/errata/RHSA-2018:2669","https://nvd.nist.gov/vuln/detail/CVE-2018-1000130","https://github.com/ARPSyndicate/cvemon","https://github.com/SexyBeast233/SecBooks"]},{"tag_id":"CVE-2018-10737","tag_type":"cve","title":"NagiosXI <= 5.4.12 logbook.php SQL injection","severity":"high","actively_exploited":false,"match_field":"url_path","matched_pattern":"/nagiosql/admin/logbook.php","reference_urls":["https://vulners.com/seebug/SSV:97267","https://nvd.nist.gov/vuln/detail/CVE-2018-10737"]},{"tag_id":"CVE-2018-10738","tag_type":"cve","title":"NagiosXI <= 5.4.12 menuaccess.php - SQL injection","severity":"high","actively_exploited":false,"match_field":"url_path","matched_pattern":"/nagiosql/admin/menuaccess.php","reference_urls":["https://qkl.seebug.org/vuldb/ssvid-97268","https://vuldb.com/de/?id.117807"]},{"tag_id":"CVE-2018-11222","tag_type":"cve","title":"Pandora FMS <=7.0NG.722 - Remote Code Execution","severity":"high","actively_exploited":false,"match_field":"url_path","matched_pattern":"/pandora_console/ajax.php","reference_urls":["https://blog.hackercat.ninja/post/pandoras_box/","https://github.com/pandorafms/pandorafms","https://nvd.nist.gov/vuln/detail/CVE-2018-11222"]},{"tag_id":"CVE-2018-11231","tag_type":"cve","title":"Opencart Divido - Sql Injection","severity":"high","actively_exploited":false,"match_field":"url_path","matched_pattern":"/upload/index.php","reference_urls":["https://web.archive.org/web/20220331072310/http://foreversong.cn/archives/1183","https://nvd.nist.gov/vuln/detail/CVE-2018-11231","http://foreversong.cn/archives/1183","https://github.com/ARPSyndicate/kenzer-templates"]},{"tag_id":"CVE-2018-12296","tag_type":"cve","title":"Seagate NAS OS 4.3.15.1 - Server Information Disclosure","severity":"high","actively_exploited":false,"match_field":"url_path","matched_pattern":"/api/external/7.0/system.System.get_infos","reference_urls":["https://blog.securityevaluators.com/invading-your-personal-cloud-ise-labs-exploits-the-seagate-stcr3000101-ecf89de2170","https://nvd.nist.gov/vuln/detail/CVE-2018-12296","https://github.com/ARPSyndicate/kenzer-templates"]},{"tag_id":"CVE-2018-2791","tag_type":"cve","title":"Oracle Fusion Middleware WebCenter Sites - Cross-Site Scripting","severity":"high","actively_exploited":false,"match_field":"url_path","matched_pattern":"/cs/Satellite?destpage=\"<h1xxx\"><script>alert(document.domain)</script>&pagename=OpenMarket%2FXcelerate%2FUIFramework%2F","reference_urls":["http://www.oracle.com/technetwork/security-advisory/cpuapr2018-3678067.html","http://web.archive.org/web/20211206165005/https://securitytracker.com/id/1040695","https://www.exploit-db.com/exploits/44752/","https://outpost24.com/blog/Vulnerabilities-discovered-in-Oracle-WebCenter-Sites","https://nvd.nist.gov/vuln/detail/CVE-2018-2791"]},{"tag_id":"CVE-2018-7467","tag_type":"cve","title":"AxxonSoft Axxon Next - Local File Inclusion","severity":"high","actively_exploited":false,"match_field":"url_path","matched_pattern":"//css//..%2f..%2f..%2f..%2f..%2f..%2f..%2f..%2f..%2f..%2f..%2f..%2f..%2f..%2f..%2f..%2f..%2f..%2fwindows\\win.ini","reference_urls":["https://packetstormsecurity.com/files/146604/AxxonSoft-Axxon-Next-Directory-Traversal.html","https://github.com/sullo/advisory-archives/blob/master/axxonsoft-next-CVE-2018-7467.txt","https://nvd.nist.gov/vuln/detail/CVE-2018-7467","http://www.projectxit.com.au/blog/2018/2/27/axxonsoft-client-directory-traversal-cve-2018-7467-axxonsoft-axxon-next-axxonsoft-client-directory-traversal-via-an-initial-css2f-substring-in-a-uri-cve-2018-7467","https://github.com/ARPSyndicate/kenzer-templates"]},{"tag_id":"CVE-2018-7719","tag_type":"cve","title":"Acrolinx Server <5.2.5 - Local File Inclusion","severity":"high","actively_exploited":false,"match_field":"url_path","matched_pattern":"/..\\..\\..\\..\\..\\..\\..\\..\\..\\..\\..\\..\\..\\..\\windows\\win.ini","reference_urls":["https://packetstormsecurity.com/files/146911/Acrolinx-Server-Directory-Traversal.html","https://support.acrolinx.com/hc/en-us/articles/213987685-Acrolinx-Server-Version-5-1-including-subsequent-service-releases-","https://www.exploit-db.com/exploits/44345/","https://nvd.nist.gov/vuln/detail/CVE-2018-7719","https://github.com/ARPSyndicate/cvemon"]},{"tag_id":"CVE-2018-8033","tag_type":"cve","title":"Apache OFBiz - XML External Entity Injection","severity":"high","actively_exploited":false,"match_field":"url_path","matched_pattern":"/webtools/control/httpService","reference_urls":["https://lists.apache.org/thread/9bym7qk6ccwwr6d3mg26thp9zyv1l06y","https://nvd.nist.gov/vuln/detail/CVE-2018-8033"]},{"tag_id":"CVE-2019-11253","tag_type":"cve","title":"Kubernetes API Server - YAML Parsing DoS (Billion Laughs)","severity":"high","actively_exploited":false,"match_field":"url_path","matched_pattern":"/apis/authorization.k8s.io/v1/selfsubjectaccessreviews","reference_urls":["https://gist.github.com/bgeesaman/0e0349e94cd22c48bf14d8a9b7d6b8f2","https://github.com/kubernetes/kubernetes/issues/83253","https://nvd.nist.gov/vuln/detail/CVE-2019-11253"]},{"tag_id":"CVE-2019-17538","tag_type":"cve","title":"Jiangnan Online Judge 0.8.0 - Local File Inclusion","severity":"high","actively_exploited":false,"match_field":"url_path","matched_pattern":"/jnoj/web/polygon/problem/viewfile?id=1&name=../../../../../../../etc/passwd","reference_urls":["https://github.com/shi-yang/jnoj/issues/53","https://nvd.nist.gov/vuln/detail/CVE-2019-17538","https://github.com/Elsfa7-110/kenzer-templates","https://github.com/ARPSyndicate/kenzer-templates"]},{"tag_id":"CVE-2019-18922","tag_type":"cve","title":"Allied Telesis AT-GS950/8 - Local File Inclusion","severity":"high","actively_exploited":false,"match_field":"url_path","matched_pattern":"/../../../../../../etc/passwd","reference_urls":["https://packetstormsecurity.com/files/155504/Allied-Telesis-AT-GS950-8-Directory-Traversal.html","https://pastebin.com/dpEGKUGz","https://nvd.nist.gov/vuln/detail/CVE-2019-18922","http://packetstormsecurity.com/files/155504/Allied-Telesis-AT-GS950-8-Directory-Traversal.html","http://seclists.org/fulldisclosure/2019/Nov/31"]},{"tag_id":"CVE-2019-20224","tag_type":"cve","title":"Pandora FMS 7.0NG - Remote Command Injection","severity":"high","actively_exploited":false,"match_field":"url_path","matched_pattern":"/pandora_console/index.php","reference_urls":["https://shells.systems/pandorafms-v7-0ng-authenticated-remote-code-execution-cve-2019-20224/","https://gist.github.com/mhaskar/2153d66a0928492d76b799ba13b9e3f9","https://nvd.nist.gov/vuln/detail/CVE-2019-20224","https://drive.google.com/file/d/1DkWR5MylzeNr20jmHXTaAIJmf3YN-lnO/view","https://pandorafms.com/downloads/solved-pandorafms-742.mp4"]},{"tag_id":"CVE-2019-6715","tag_type":"cve","title":"W3 Total Cache 0.9.2.6-0.9.3 - Unauthenticated File Read / Directory Traversal","severity":"high","actively_exploited":false,"match_field":"url_path","matched_pattern":"/wp-content/plugins/w3-total-cache/pub/sns.php","reference_urls":["https://vinhjaxt.github.io/2019/03/cve-2019-6715","http://packetstormsecurity.com/files/160674/WordPress-W3-Total-Cache-0.9.3-File-Read-Directory-Traversal.html","https://nvd.nist.gov/vuln/detail/CVE-2019-6715","https://github.com/sobinge/nuclei-templates","https://github.com/random-robbie/cve-2019-6715"]},{"tag_id":"CVE-2019-7315","tag_type":"cve","title":"Genie Access WIP3BVAF IP Camera - Local File Inclusion","severity":"high","actively_exploited":false,"match_field":"url_path","matched_pattern":"/../../../../../etc/passwd","reference_urls":["https://labs.nettitude.com/blog/cve-2019-7315-genie-access-wip3bvaf-ip-camera-directory-traversal/","https://vuldb.com/?id.136593","https://nvd.nist.gov/vuln/detail/CVE-2019-7315","https://github.com/ARPSyndicate/kenzer-templates"]},{"tag_id":"CVE-2020-11991","tag_type":"cve","title":"Apache Cocoon 2.1.12 - XML Injection","severity":"high","actively_exploited":false,"match_field":"url_path","matched_pattern":"/v2/api/product/manger/getInfo","reference_urls":["https://lists.apache.org/thread/6xg5j4knfczwdhggo3t95owqzol37k1b","https://nvd.nist.gov/vuln/detail/CVE-2020-11991","https://lists.apache.org/thread.html/r77add973ea521185e1a90aca00ba9dae7caa8d8b944d92421702bb54%40%3Cusers.cocoon.apache.org%3E","https://github.com/ARPSyndicate/cvemon","https://github.com/H4ckTh3W0r1d/Goby_POC"]},{"tag_id":"CVE-2020-13851","tag_type":"cve","title":"Artica Pandora FMS 7.44 - Remote Code Execution","severity":"high","actively_exploited":false,"match_field":"url_path","matched_pattern":"/pandora_console/ajax.php?page=include/ajax/events&perform_event_response=10000000&target=cat+/etc/passwd&response_id=1","reference_urls":["https://packetstormsecurity.com/files/158390/Pandora-FMS-7.0-NG-7XX-Remote-Command-Execution.html","https://nvd.nist.gov/vuln/detail/CVE-2020-13851","https://www.coresecurity.com/advisories","https://github.com/hadrian3689/pandorafms_7.44"]},{"tag_id":"CVE-2020-17505","tag_type":"cve","title":"Artica Web Proxy 4.30 - OS Command Injection","severity":"high","actively_exploited":false,"match_field":"url_path","matched_pattern":"/cyrus.index.php?service-cmds-peform=%7C%7Cwhoami%7C%7C","reference_urls":["http://packetstormsecurity.com/files/159267/Artica-Proxy-4.30.000000-Authentication-Bypass-Command-Injection.html","https://nvd.nist.gov/vuln/detail/CVE-2020-17505","https://blog.max0x4141.com/post/artica_proxy/","https://github.com/sobinge/nuclei-templates","https://github.com/ARPSyndicate/kenzer-templates"]},{"tag_id":"CVE-2020-17518","tag_type":"cve","title":"Apache Flink 1.5.1 - Local File Inclusion","severity":"high","actively_exploited":false,"match_field":"url_path","matched_pattern":"/jobmanager/logs/..%252f..%252f..%252f..%252f..%252f..%252f..%252f..%252f..%252f..%252f..%252f..%252ftmp%252fpoc","reference_urls":["https://github.com/vulhub/vulhub/tree/master/flink/CVE-2020-17518","https://lists.apache.org/thread.html/rb43cd476419a48be89c1339b527a18116f23eec5b6df2b2acbfef261%40%3Cdev.flink.apache.org%3E","https://lists.apache.org/thread.html/rb43cd476419a48be89c1339b527a18116f23eec5b6df2b2acbfef261@%3Cuser.flink.apache.org%3E","https://lists.apache.org/thread.html/rb43cd476419a48be89c1339b527a18116f23eec5b6df2b2acbfef261@%3Cdev.flink.apache.org%3E","https://nvd.nist.gov/vuln/detail/CVE-2020-17518"]},{"tag_id":"CVE-2020-24579","tag_type":"cve","title":"D-Link DSL 2888a - Authentication Bypass/Remote Command Execution","severity":"high","actively_exploited":false,"match_field":"url_path","matched_pattern":"/cgi-bin/execute_cmd.cgi?timestamp=1589333279490&cmd=cat%20/etc/passwd","reference_urls":["https://www.trustwave.com/en-us/resources/blogs/spiderlabs-blog/d-link-multiple-security-vulnerabilities-leading-to-rce/","https://www.trustwave.com/en-us/resources/security-resources/security-advisories/","https://nvd.nist.gov/vuln/detail/CVE-2020-24579","https://github.com/ARPSyndicate/kenzer-templates","https://github.com/Elsfa7-110/kenzer-templates"]},{"tag_id":"CVE-2020-25780","tag_type":"cve","title":"Commvault CommCell - Local File Inclusion","severity":"high","actively_exploited":false,"match_field":"url_path","matched_pattern":"/SearchSvc/CVSearchService.svc","reference_urls":["https://srcincite.io/blog/2021/11/22/unlocking-the-vault.html","http://kb.commvault.com/article/63264","https://nvd.nist.gov/vuln/detail/CVE-2020-25780","https://github.com/ARPSyndicate/cvemon","https://github.com/ARPSyndicate/kenzer-templates"]},{"tag_id":"CVE-2023-39141","tag_type":"cve","title":"Aria2 WebUI - Path traversal","severity":"high","actively_exploited":false,"match_field":"url_path","matched_pattern":"/../../../../etc/passwd","reference_urls":["https://twitter.com/win3zz/status/1694239332465520684","https://gist.github.com/JafarAkhondali/528fe6c548b78f454911fb866b23f66e","https://github.com/ziahamza/webui-aria2/blob/109903f0e2774cf948698cd95a01f77f33d7dd2c/node-server.js#L10","https://github.com/codeb0ss/CVE-2023-39141-PoC","https://github.com/nomi-sec/PoC-in-GitHub"]},{"tag_id":"CVE-2025-3515","tag_type":"cve","title":"Contact Form 7 Drag and Drop Multiple File Upload - Arbitrary File Upload","severity":"high","actively_exploited":false,"match_field":"url_path","matched_pattern":"/wp-content/uploads/wp_dndcf7_uploads/wpcf7-files","reference_urls":["https://nvd.nist.gov/vuln/detail/CVE-2025-3515","https://plugins.trac.wordpress.org/changeset/3310153/","https://www.wordfence.com/threat-intel/vulnerabilities/id/e1298242-61d2-495e-bae7-96b5e12bd03d"]},{"tag_id":"CVE-2007-4556","tag_type":"cve","title":"OpenSymphony XWork/Apache Struts2 - Remote Code Execution","severity":"medium","actively_exploited":false,"match_field":"url_path","matched_pattern":"/login.action","reference_urls":["https://www.guildhab.top/?p=2326","https://nvd.nist.gov/vuln/detail/CVE-2007-4556","https://cwiki.apache.org/confluence/display/WW/S2-001","http://forums.opensymphony.com/ann.jspa?annID=54","http://issues.apache.org/struts/browse/WW-2030"]},{"tag_id":"CVE-2022-31798","tag_type":"cve","title":"Nortek Linear eMerge E3-Series - Cross-Site Scripting","severity":"medium","actively_exploited":false,"match_field":"url_path","matched_pattern":"/card_scan.php","reference_urls":["https://packetstormsecurity.com/files/167992/","http://packetstormsecurity.com/files/167992/Nortek-Linear-eMerge-E3-Series-Account-Takeover.html","https://nvd.nist.gov/vuln/detail/CVE-2022-31798","https://eg.linkedin.com/in/omar-1-hashem","https://gist.github.com/omarhashem123/bccdcec70ab7e8f00519d56ea2e3fd79"]},{"tag_id":"CVE-2022-37153","tag_type":"cve","title":"Artica Proxy 4.30.000000 - Cross-Site Scripting","severity":"medium","actively_exploited":false,"match_field":"url_path","matched_pattern":"/fw.login.php","reference_urls":["https://github.com/Fjowel/CVE-2022-37153","https://nvd.nist.gov/vuln/detail/CVE-2022-37153","https://github.com/SYRTI/POC_to_review","https://github.com/WhooAmii/POC_to_review","https://github.com/k0mi-tg/CVE-POC"]}],"data_as_of":"2026-08-20T21:23:16.984564+00:00"}