{"ip":"159.65.226.156","total_events":80,"verdict":{"verdict":"scanner","label":"Recognized scanner","detail":"BinaryEdge","confidence":"high","network_type":"CDN","why":["Source IP is in a known scanner range (BinaryEdge).","Known research and commercial scanners are labelled as such, not as threats."]},"first_seen":"2026-06-02T23:25:39","last_seen":"2026-06-07T05:36:15","events_24h":0,"events_7d":0,"geo":{"country_code":"US","country_name":"United States","region":"New Jersey","city":"North Bergen","lat":40.7964,"lon":-74.0203,"asn":14061,"org":"DigitalOcean, LLC"},"source_domain":"prod-bromine-nyc1-160.do.binaryedge.ninja","known_scanners":["BinaryEdge"],"scanner_tag":{"key":"binaryedge","label":"BinaryEdge","category":"commercial","url":"https://www.binaryedge.io/"},"cve_matches":[{"cve_id":"CVE-2018-13379","title":"Fortinet FortiOS - Credentials Disclosure","severity":"critical","actively_exploited":true,"match_field":"url_path","matched_pattern":"/remote/fgt_lang?lang=/../../../..//////////dev/cmdb/sslvpn_websession"},{"cve_id":"CVE-2021-22205","title":"GitLab CE/EE - Remote Code Execution","severity":"critical","actively_exploited":true,"match_field":"url_path","matched_pattern":"/users/sign_in"},{"cve_id":"CVE-2022-40684","title":"Fortinet - Authentication Bypass","severity":"critical","actively_exploited":true,"match_field":"url_path","matched_pattern":"/api/v2/cmdb/system/admin"},{"cve_id":"CVE-2023-40044","title":"WS_FTP Server - Insecure Deserialization","severity":"critical","actively_exploited":true,"match_field":"url_path","matched_pattern":"/AHT/AHT_UI/public/js/app.min.js"},{"cve_id":"CVE-2024-0012","title":"PAN-OS Management Web Interface - Authentication Bypass","severity":"critical","actively_exploited":true,"match_field":"url_path","matched_pattern":"/php/ztp_gate.php/.js.map"},{"cve_id":"CVE-2024-4040","title":"CrushFTP VFS - Sandbox Escape LFR","severity":"critical","actively_exploited":true,"match_field":"url_path","matched_pattern":"/WebInterface"},{"cve_id":"CVE-2025-0282","title":"Ivanti Connect Secure - Stack-based Buffer Overflow","severity":"critical","actively_exploited":true,"match_field":"url_path","matched_pattern":"/dana-na/auth/url_default/welcome.cgi"},{"cve_id":"CVE-2020-3452","title":"Cisco Adaptive Security Appliance (ASA)/Firepower Threat Defense (FTD) - Local File Inclusion","severity":"high","actively_exploited":true,"match_field":"url_path","matched_pattern":"/+CSCOT+/oem-customization?app=AnyConnect&type=oem&platform=..&resource-type=..&name=%2bCSCOE%2b/portal_inc.lua"},{"cve_id":"CVE-2023-7028","title":"GitLab - Account Takeover via Password Reset","severity":"high","actively_exploited":true,"match_field":"url_path","matched_pattern":"/users/sign_in"},{"cve_id":"CVE-2017-5983","title":"JIRA Workflow Designer Plugin in Atlassian JIRA Server > 6.3.0 - Remote Code Execution (XXE)","severity":"critical","actively_exploited":false,"match_field":"url_path","matched_pattern":"/jira/secure/Dashboard.jspa"},{"cve_id":"CVE-2022-0735","title":"GitLab CE/EE - Information Disclosure","severity":"critical","actively_exploited":false,"match_field":"url_path","matched_pattern":"/users/sign_in"},{"cve_id":"CVE-2022-1162","title":"GitLab CE/EE - Hard-Coded Credentials","severity":"critical","actively_exploited":false,"match_field":"url_path","matched_pattern":"/users/sign_in"},{"cve_id":"CVE-2023-43177","title":"CrushFTP < 10.5.1 - Unauthenticated Remote Code Execution","severity":"critical","actively_exploited":false,"match_field":"url_path","matched_pattern":"/WebInterface"},{"cve_id":"CVE-2020-2036","title":"Palo Alto Networks PAN-OS Web Interface - Cross Site-Scripting","severity":"high","actively_exploited":false,"match_field":"url_path","matched_pattern":"/global-protect/login.esp"},{"cve_id":"CVE-2022-2185","title":"GitLab CE/EE - Remote Code Execution","severity":"high","actively_exploited":false,"match_field":"url_path","matched_pattern":"/users/sign_in"},{"cve_id":"CVE-2023-2825","title":"GitLab 16.0.0 - Path Traversal","severity":"high","actively_exploited":false,"match_field":"url_path","matched_pattern":"/users/sign_in"},{"cve_id":"CVE-2007-4556","title":"OpenSymphony XWork/Apache Struts2 - Remote Code Execution","severity":"medium","actively_exploited":false,"match_field":"url_path","matched_pattern":"/login.action"},{"cve_id":"CVE-2019-11507","title":"Pulse Secure Pulse Connect Secure - Cross-Site Scripting (Reflected)","severity":"medium","actively_exploited":false,"match_field":"url_path","matched_pattern":"/dana-na/auth/url_default/welcome.cgi"}],"malware":[],"top_ports":[{"port":8443,"proto":"tcp","label":"HTTPS-alt","count":79},{"port":2103,"proto":"tcp","label":"","count":1}],"fingerprints":{"ssh_hassh":[],"tls_ja4":["t13i3112h1_e8f1e7e78f70_d339722ba4af"],"tls_ja3":["48eb9b1182293f55c0710654b7b12fc6"],"ja4h":["ge11nn0300_dedeb29cc523"]},"fingerprint_peers":{"t13i3112h1_e8f1e7e78f70_d339722ba4af":41,"ge11nn0300_dedeb29cc523":92},"user_agents":["Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/83.0.4103.61 Safari/537.36"],"timeline":[{"date":"2026-06-02","count":79},{"date":"2026-06-07","count":1}],"recent_events":[{"timestamp":"2026-06-07T05:36:15","port":2103,"proto":"tcp","app_proto":"tls","app_protocol":"http","host":"<HONEYPOT>","headers":"{\"accept-encoding\":\"gzip, deflate\",\"host\":\"<HONEYPOT>:2103\",\"user-agent\":\"Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/83.0.4103.61 Safari/537.36\"}","body":"","sni":"","tls_cipher":"TLS_AES_128_GCM_SHA256","tls_version":"TLSv1.3","alpn":["http/1.1"],"url_path":"/","summary":"","payload_hex":"474554202f20485454502f312e310d0a4163636570742d456e636f64696e673a20677a69702c206465666c6174650d0a557365722d4167656e743a204d6f7a696c6c612f352e30202857696e646f7773204e542031302e303b2057696e36343b2078363429204170706c655765624b69742f3533372e333620284b48544d4c2c206c696b65204765636b6f29204368726f6d652f38332e302e343130332e3631205361666172692f3533372e33360d0a486f73743a20<HONEYPOT>3a323130330d0a0d0a","method":"GET","user_agent":"Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/83.0.4103.61 Safari/537.36","community_id":"1:17cpU9WefznrLivlSFtN+cEtWBA=","ja3":"48eb9b1182293f55c0710654b7b12fc6","session":"a1e3150b-bb79-489e-a545-db13a785067e","seq":1,"duration_ms":113,"bytes_in":205,"bytes_out":79},{"timestamp":"2026-06-02T23:40:05","port":8443,"proto":"tcp","app_proto":"tls","app_protocol":"http","host":"<HONEYPOT>","headers":"{\"accept-encoding\":\"gzip, deflate\",\"host\":\"<HONEYPOT>:8443\",\"user-agent\":\"Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/83.0.4103.61 Safari/537.36\"}","body":"","sni":"","tls_cipher":"TLS_AES_128_GCM_SHA256","tls_version":"TLSv1.3","alpn":["http/1.1"],"url_path":"/wsman","summary":"","payload_hex":"474554202f77736d616e20485454502f312e310d0a4163636570742d456e636f64696e673a20677a69702c206465666c6174650d0a557365722d4167656e743a204d6f7a696c6c612f352e30202857696e646f7773204e542031302e303b2057696e36343b2078363429204170706c655765624b69742f3533372e333620284b48544d4c2c206c696b65204765636b6f29204368726f6d652f38332e302e343130332e3631205361666172692f3533372e33360d0a486f73743a20<HONEYPOT>3a383434330d0a0d0a","method":"GET","user_agent":"Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/83.0.4103.61 Safari/537.36","community_id":"1:Cs+qlItOfmQRN988DBjSx+90/R4=","ja3":"","session":"03c3fd87-a794-4106-969d-91390a0ccecb","seq":0,"duration_ms":0,"bytes_in":0,"bytes_out":0},{"timestamp":"2026-06-02T23:39:50","port":8443,"proto":"tcp","app_proto":"tls","app_protocol":"http","host":"<HONEYPOT>","headers":"{\"accept-encoding\":\"gzip, deflate\",\"host\":\"<HONEYPOT>:8443\",\"user-agent\":\"Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/83.0.4103.61 Safari/537.36\"}","body":"","sni":"","tls_cipher":"TLS_AES_128_GCM_SHA256","tls_version":"TLSv1.3","alpn":["http/1.1"],"url_path":"/webui/","summary":"","payload_hex":"474554202f77656275692f20485454502f312e310d0a4163636570742d456e636f64696e673a20677a69702c206465666c6174650d0a557365722d4167656e743a204d6f7a696c6c612f352e30202857696e646f7773204e542031302e303b2057696e36343b2078363429204170706c655765624b69742f3533372e333620284b48544d4c2c206c696b65204765636b6f29204368726f6d652f38332e302e343130332e3631205361666172692f3533372e33360d0a486f73743a20<HONEYPOT>3a383434330d0a0d0a","method":"GET","user_agent":"Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/83.0.4103.61 Safari/537.36","community_id":"1:vM80bOU0QsDVDTpzcqgnMu4TIlk=","ja3":"","session":"8cde4f27-c904-42cd-865b-7ed77bb48c63","seq":0,"duration_ms":0,"bytes_in":0,"bytes_out":0},{"timestamp":"2026-06-02T23:39:34","port":8443,"proto":"tcp","app_proto":"tls","app_protocol":"http","host":"<HONEYPOT>","headers":"{\"accept-encoding\":\"gzip, deflate\",\"host\":\"<HONEYPOT>:8443\",\"user-agent\":\"Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/83.0.4103.61 Safari/537.36\"}","body":"","sni":"","tls_cipher":"TLS_AES_128_GCM_SHA256","tls_version":"TLSv1.3","alpn":["http/1.1"],"url_path":"/webconsole","summary":"","payload_hex":"474554202f776562636f6e736f6c6520485454502f312e310d0a4163636570742d456e636f64696e673a20677a69702c206465666c6174650d0a557365722d4167656e743a204d6f7a696c6c612f352e30202857696e646f7773204e542031302e303b2057696e36343b2078363429204170706c655765624b69742f3533372e333620284b48544d4c2c206c696b65204765636b6f29204368726f6d652f38332e302e343130332e3631205361666172692f3533372e33360d0a486f73743a20<HONEYPOT>3a383434330d0a0d0a","method":"GET","user_agent":"Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/83.0.4103.61 Safari/537.36","community_id":"1:XWVMX/wHB5dNVsmHiJj5JJwIzfw=","ja3":"","session":"a3435588-8240-4524-9d5e-bb49290af83c","seq":0,"duration_ms":0,"bytes_in":0,"bytes_out":0},{"timestamp":"2026-06-02T23:39:25","port":8443,"proto":"tcp","app_proto":"tls","app_protocol":"http","host":"<HONEYPOT>","headers":"{\"accept-encoding\":\"gzip, deflate\",\"host\":\"<HONEYPOT>:8443\",\"user-agent\":\"Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/83.0.4103.61 Safari/537.36\"}","body":"","sni":"","tls_cipher":"TLS_AES_128_GCM_SHA256","tls_version":"TLSv1.3","alpn":["http/1.1"],"url_path":"/webclient/Login.xhtml","summary":"","payload_hex":"474554202f776562636c69656e742f4c6f67696e2e7868746d6c20485454502f312e310d0a4163636570742d456e636f64696e673a20677a69702c206465666c6174650d0a557365722d4167656e743a204d6f7a696c6c612f352e30202857696e646f7773204e542031302e303b2057696e36343b2078363429204170706c655765624b69742f3533372e333620284b48544d4c2c206c696b65204765636b6f29204368726f6d652f38332e302e343130332e3631205361666172692f3533372e33360d0a486f73743a20<HONEYPOT>3a383434330d0a0d0a","method":"GET","user_agent":"Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/83.0.4103.61 Safari/537.36","community_id":"1:T034yMj3Z9GWsz7h0Le5nG6nlgY=","ja3":"","session":"34227ed5-d8d6-4526-b9d8-efa7b93268c2","seq":0,"duration_ms":0,"bytes_in":0,"bytes_out":0},{"timestamp":"2026-06-02T23:39:18","port":8443,"proto":"tcp","app_proto":"tls","app_protocol":"http","host":"<HONEYPOT>","headers":"{\"accept-encoding\":\"gzip, deflate\",\"host\":\"<HONEYPOT>:8443\",\"user-agent\":\"Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/83.0.4103.61 Safari/537.36\"}","body":"","sni":"","tls_cipher":"TLS_AES_128_GCM_SHA256","tls_version":"TLSv1.3","alpn":["http/1.1"],"url_path":"/webapps/login","summary":"","payload_hex":"474554202f776562617070732f6c6f67696e20485454502f312e310d0a4163636570742d456e636f64696e673a20677a69702c206465666c6174650d0a557365722d4167656e743a204d6f7a696c6c612f352e30202857696e646f7773204e542031302e303b2057696e36343b2078363429204170706c655765624b69742f3533372e333620284b48544d4c2c206c696b65204765636b6f29204368726f6d652f38332e302e343130332e3631205361666172692f3533372e33360d0a486f73743a20<HONEYPOT>3a383434330d0a0d0a","method":"GET","user_agent":"Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/83.0.4103.61 Safari/537.36","community_id":"1:kji3BT3ycWt9o+tcYXx+9bHQRx0=","ja3":"","session":"fa3c6f2e-2ce0-4170-a82c-a203961eaa7c","seq":0,"duration_ms":0,"bytes_in":0,"bytes_out":0},{"timestamp":"2026-06-02T23:39:11","port":8443,"proto":"tcp","app_proto":"tls","app_protocol":"http","host":"<HONEYPOT>","headers":"{\"accept-encoding\":\"gzip, deflate\",\"host\":\"<HONEYPOT>:8443\",\"user-agent\":\"Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/83.0.4103.61 Safari/537.36\"}","body":"","sni":"","tls_cipher":"TLS_AES_128_GCM_SHA256","tls_version":"TLSv1.3","alpn":["http/1.1"],"url_path":"/web/login","summary":"","payload_hex":"474554202f7765622f6c6f67696e20485454502f312e310d0a4163636570742d456e636f64696e673a20677a69702c206465666c6174650d0a557365722d4167656e743a204d6f7a696c6c612f352e30202857696e646f7773204e542031302e303b2057696e36343b2078363429204170706c655765624b69742f3533372e333620284b48544d4c2c206c696b65204765636b6f29204368726f6d652f38332e302e343130332e3631205361666172692f3533372e33360d0a486f73743a20<HONEYPOT>3a383434330d0a0d0a","method":"GET","user_agent":"Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/83.0.4103.61 Safari/537.36","community_id":"1:yJzyMCu5iQ9mNA0BHk5U/Cvg4wU=","ja3":"","session":"25bdac86-6aa5-45a2-a084-a3c5ec70bbdd","seq":0,"duration_ms":0,"bytes_in":0,"bytes_out":0},{"timestamp":"2026-06-02T23:39:03","port":8443,"proto":"tcp","app_proto":"tls","app_protocol":"http","host":"<HONEYPOT>","headers":"{\"accept-encoding\":\"gzip, deflate\",\"host\":\"<HONEYPOT>:8443\",\"user-agent\":\"Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/83.0.4103.61 Safari/537.36\"}","body":"","sni":"","tls_cipher":"TLS_AES_128_GCM_SHA256","tls_version":"TLSv1.3","alpn":["http/1.1"],"url_path":"/vpn/index.html","summary":"","payload_hex":"474554202f76706e2f696e6465782e68746d6c20485454502f312e310d0a4163636570742d456e636f64696e673a20677a69702c206465666c6174650d0a557365722d4167656e743a204d6f7a696c6c612f352e30202857696e646f7773204e542031302e303b2057696e36343b2078363429204170706c655765624b69742f3533372e333620284b48544d4c2c206c696b65204765636b6f29204368726f6d652f38332e302e343130332e3631205361666172692f3533372e33360d0a486f73743a20<HONEYPOT>3a383434330d0a0d0a","method":"GET","user_agent":"Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/83.0.4103.61 Safari/537.36","community_id":"1:SWxdt35nG1OnSn+B3AEGEkf0rus=","ja3":"","session":"da6838cd-bd12-4802-88ee-77f00d7f7622","seq":0,"duration_ms":0,"bytes_in":0,"bytes_out":0},{"timestamp":"2026-06-02T23:38:54","port":8443,"proto":"tcp","app_proto":"tls","app_protocol":"http","host":"<HONEYPOT>","headers":"{\"accept-encoding\":\"gzip, deflate\",\"host\":\"<HONEYPOT>:8443\",\"user-agent\":\"Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/83.0.4103.61 Safari/537.36\"}","body":"","sni":"","tls_cipher":"TLS_AES_128_GCM_SHA256","tls_version":"TLSv1.3","alpn":["http/1.1"],"url_path":"/users/sign_in","summary":"","payload_hex":"474554202f75736572732f7369676e5f696e20485454502f312e310d0a4163636570742d456e636f64696e673a20677a69702c206465666c6174650d0a557365722d4167656e743a204d6f7a696c6c612f352e30202857696e646f7773204e542031302e303b2057696e36343b2078363429204170706c655765624b69742f3533372e333620284b48544d4c2c206c696b65204765636b6f29204368726f6d652f38332e302e343130332e3631205361666172692f3533372e33360d0a486f73743a20<HONEYPOT>3a383434330d0a0d0a","method":"GET","user_agent":"Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/83.0.4103.61 Safari/537.36","community_id":"1:ixDuBPv0QAnx4Q26/xx9H9Txklo=","ja3":"","session":"770e8125-f90e-4196-97af-0a7b410927b1","seq":0,"duration_ms":0,"bytes_in":0,"bytes_out":0},{"timestamp":"2026-06-02T23:38:48","port":8443,"proto":"tcp","app_proto":"tls","app_protocol":"http","host":"<HONEYPOT>","headers":"{\"accept-encoding\":\"gzip, deflate\",\"host\":\"<HONEYPOT>:8443\",\"user-agent\":\"Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/83.0.4103.61 Safari/537.36\"}","body":"","sni":"","tls_cipher":"TLS_AES_128_GCM_SHA256","tls_version":"TLSv1.3","alpn":["http/1.1"],"url_path":"/sslvpn/Login/Login","summary":"","payload_hex":"474554202f73736c76706e2f4c6f67696e2f4c6f67696e20485454502f312e310d0a4163636570742d456e636f64696e673a20677a69702c206465666c6174650d0a557365722d4167656e743a204d6f7a696c6c612f352e30202857696e646f7773204e542031302e303b2057696e36343b2078363429204170706c655765624b69742f3533372e333620284b48544d4c2c206c696b65204765636b6f29204368726f6d652f38332e302e343130332e3631205361666172692f3533372e33360d0a486f73743a20<HONEYPOT>3a383434330d0a0d0a","method":"GET","user_agent":"Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/83.0.4103.61 Safari/537.36","community_id":"1:pJGlR5UFQVnP1gZ9nv0ACdQdEck=","ja3":"","session":"de9fbbf6-df44-4345-990d-b8647453dce2","seq":0,"duration_ms":0,"bytes_in":0,"bytes_out":0}],"http_methods":[{"method":"GET","count":80}],"distinct_ports_total":2,"top_paths":[{"path":"/","count":2,"ports":2},{"path":"/client","count":1,"ports":1},{"path":"/dana-na/nc/nc_gina_ver.txt","count":1,"ports":1},{"path":"/remote","count":1,"ports":1},{"path":"/login","count":1,"ports":1},{"path":"/.env","count":1,"ports":1},{"path":"/rdweb","count":1,"ports":1},{"path":"/admin","count":1,"ports":1},{"path":"/mftp","count":1,"ports":1},{"path":"/webui/","count":1,"ports":1},{"path":"/wsman","count":1,"ports":1},{"path":"/Login.jsp","count":1,"ports":1},{"path":"/configurations","count":1,"ports":1},{"path":"/login.action","count":1,"ports":1},{"path":"/human.aspx","count":1,"ports":1}],"distinct_paths_total":79,"top_snis":[],"top_hosts":[],"top_alpns":[{"value":"http/1.1","count":80}],"banners":[],"credentials":[],"header_profile":{"signature":["Accept-Encoding","Host","User-Agent"],"representative":[{"name":"Accept-Encoding","value":"gzip, deflate","notable":false},{"name":"Host","value":"<HONEYPOT>:2103","notable":false},{"name":"User-Agent","value":"Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/83.0.4103.61 Safari/537.36","notable":false}],"distinct_sets":1,"events_with_headers":10},"tags":[{"tag_id":"CVE-2018-13379","tag_type":"cve","title":"Fortinet FortiOS - Credentials Disclosure","severity":"critical","actively_exploited":true,"match_field":"url_path","matched_pattern":"/remote/fgt_lang?lang=/../../../..//////////dev/cmdb/sslvpn_websession","reference_urls":["https://fortiguard.com/advisory/FG-IR-18-384","https://www.fortiguard.com/psirt/FG-IR-20-233","https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-13379"]},{"tag_id":"CVE-2021-22205","tag_type":"cve","title":"GitLab CE/EE - Remote Code Execution","severity":"critical","actively_exploited":true,"match_field":"url_path","matched_pattern":"/users/sign_in","reference_urls":["https://gitlab.com/gitlab-com/gl-security/security-operations/gl-redteam/red-team-research/cve-2021-22205-hash-generator","https://gitlab.com/gitlab-com/gl-security/security-operations/gl-redteam/red-team-operations/-/issues/196","https://gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-22205.json","https://censys.io/blog/cve-2021-22205-it-was-a-gitlab-smash/","https://security.humanativaspa.it/gitlab-ce-cve-2021-22205-in-the-wild/"]},{"tag_id":"CVE-2022-40684","tag_type":"cve","title":"Fortinet - Authentication Bypass","severity":"critical","actively_exploited":true,"match_field":"url_path","matched_pattern":"/api/v2/cmdb/system/admin","reference_urls":["https://github.com/horizon3ai/CVE-2022-40684/blob/master/CVE-2022-40684.py","https://securityonline.info/researchers-have-developed-cve-2022-40684-poc-exploit-code/","https://socradar.io/what-do-you-need-to-know-about-fortinet-critical-authentication-bypass-vulnerability-cve-2022-40684/","https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-40684","https://nvd.nist.gov/vuln/detail/CVE-2022-40684"]},{"tag_id":"CVE-2023-40044","tag_type":"cve","title":"WS_FTP Server - Insecure Deserialization","severity":"critical","actively_exploited":true,"match_field":"url_path","matched_pattern":"/AHT/AHT_UI/public/js/app.min.js","reference_urls":["https://attackerkb.com/topics/bn32f9sNax/cve-2023-40044","https://censys.com/cve-2023-40044/","https://www.progress.com/ws_ftp","https://www.rapid7.com/blog/post/2023/09/29/etr-critical-vulnerabilities-in-ws_ftp-server/","https://www.theregister.com/2023/10/02/ws_ftp_update/"]},{"tag_id":"CVE-2024-0012","tag_type":"cve","title":"PAN-OS Management Web Interface - Authentication Bypass","severity":"critical","actively_exploited":true,"match_field":"url_path","matched_pattern":"/php/ztp_gate.php/.js.map","reference_urls":["https://security.paloaltonetworks.com/CVE-2024-0012","https://labs.watchtowr.com/pots-and-pans-aka-an-sslvpn-palo-alto-pan-os-cve-2024-0012-and-cve-2024-9474/","https://nvd.nist.gov/vuln/detail/CVE-2024-0012"]},{"tag_id":"CVE-2024-4040","tag_type":"cve","title":"CrushFTP VFS - Sandbox Escape LFR","severity":"critical","actively_exploited":true,"match_field":"url_path","matched_pattern":"/WebInterface","reference_urls":["https://www.bleepingcomputer.com/news/security/crushftp-warns-users-to-patch-exploited-zero-day-immediately/","https://www.crushftp.com/crush10wiki/Wiki.jsp?page=Update","https://www.reddit.com/r/crowdstrike/comments/1c88788/situational_awareness_20240419_crushftp_virtual/","https://www.reddit.com/r/cybersecurity/comments/1c850i2/all_versions_of_crush_ftp_are_vulnerable/"]},{"tag_id":"CVE-2025-0282","tag_type":"cve","title":"Ivanti Connect Secure - Stack-based Buffer Overflow","severity":"critical","actively_exploited":true,"match_field":"url_path","matched_pattern":"/dana-na/auth/url_default/welcome.cgi","reference_urls":["https://forums.ivanti.com/s/article/Security-Advisory-Ivanti-Connect-Secure-Policy-Secure-ZTA-Gateways-CVE-2025-0282-CVE-2025-0283","https://labs.watchtowr.com/exploitation-walkthrough-and-techniques-ivanti-connect-secure-rce-cve-2025-0282/","https://cloud.google.com/blog/topics/threat-intelligence/ivanti-connect-secure-vpn-zero-day","https://nvd.nist.gov/vuln/detail/CVE-2025-0282"]},{"tag_id":"CVE-2020-3452","tag_type":"cve","title":"Cisco Adaptive Security Appliance (ASA)/Firepower Threat Defense (FTD) - Local File Inclusion","severity":"high","actively_exploited":true,"match_field":"url_path","matched_pattern":"/+CSCOT+/oem-customization?app=AnyConnect&type=oem&platform=..&resource-type=..&name=%2bCSCOE%2b/portal_inc.lua","reference_urls":["https://twitter.com/aboul3la/status/1286012324722155525","http://packetstormsecurity.com/files/158646/Cisco-ASA-FTD-Remote-File-Disclosure.html","http://packetstormsecurity.com/files/158647/Cisco-Adaptive-Security-Appliance-Software-9.11-Local-File-Inclusion.html","http://packetstormsecurity.com/files/159523/Cisco-ASA-FTD-9.6.4.42-Path-Traversal.html","http://packetstormsecurity.com/files/160497/Cisco-ASA-9.14.1.10-FTD-6.6.0.1-Path-Traversal.html"]},{"tag_id":"CVE-2023-7028","tag_type":"cve","title":"GitLab - Account Takeover via Password Reset","severity":"high","actively_exploited":true,"match_field":"url_path","matched_pattern":"/users/sign_in","reference_urls":["https://about.gitlab.com/releases/2024/01/11/critical-security-release-gitlab-16-7-2-released/","https://x.com/rwincey/status/1745659710089437368?s=20","https://gitlab.com/gitlab-org/gitlab/-/issues/436084","https://hackerone.com/reports/2293343","https://github.com/V1lu0/CVE-2023-7028"]},{"tag_id":"CVE-2017-5983","tag_type":"cve","title":"JIRA Workflow Designer Plugin in Atlassian JIRA Server > 6.3.0 - Remote Code Execution (XXE)","severity":"critical","actively_exploited":false,"match_field":"url_path","matched_pattern":"/jira/secure/Dashboard.jspa","reference_urls":["https://nvd.nist.gov/vuln/detail/CVE-2017-5983","https://code-white.com/blog/2017-04-amf/"]},{"tag_id":"CVE-2022-0735","tag_type":"cve","title":"GitLab CE/EE - Information Disclosure","severity":"critical","actively_exploited":false,"match_field":"url_path","matched_pattern":"/users/sign_in","reference_urls":["https://gitlab.com/gitlab-com/gl-security/threatmanagement/redteam/redteam-public/cve-hash-harvester","https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-0735.json","https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-0735","https://nvd.nist.gov/vuln/detail/cve-2022-0735","https://gitlab.com/gitlab-org/gitlab/-/issues/353529"]},{"tag_id":"CVE-2022-1162","tag_type":"cve","title":"GitLab CE/EE - Hard-Coded Credentials","severity":"critical","actively_exploited":false,"match_field":"url_path","matched_pattern":"/users/sign_in","reference_urls":["https://gitlab.com/gitlab-com/gl-security/threatmanagement/redteam/redteam-public/cve-hash-harvester","https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-1162.json","https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-1162","http://packetstormsecurity.com/files/166828/Gitlab-14.9-Authentication-Bypass.html","https://nvd.nist.gov/vuln/detail/cve-2022-1162"]},{"tag_id":"CVE-2023-43177","tag_type":"cve","title":"CrushFTP < 10.5.1 - Unauthenticated Remote Code Execution","severity":"critical","actively_exploited":false,"match_field":"url_path","matched_pattern":"/WebInterface","reference_urls":["https://nvd.nist.gov/vuln/detail/CVE-2023-43177","https://convergetp.com/2023/11/16/crushftp-zero-day-cve-2023-43177-discovered/","https://blog.projectdiscovery.io/crushftp-rce/","https://github.com/the-emmons/CVE-Disclosures/blob/main/Pending/CrushFTP-2023-1.md","https://github.com/nomi-sec/PoC-in-GitHub"]},{"tag_id":"CVE-2020-2036","tag_type":"cve","title":"Palo Alto Networks PAN-OS Web Interface - Cross Site-Scripting","severity":"high","actively_exploited":false,"match_field":"url_path","matched_pattern":"/global-protect/login.esp","reference_urls":["https://swarm.ptsecurity.com/swarm-of-palo-alto-pan-os-vulnerabilities/","https://security.paloaltonetworks.com/CVE-2020-2036","https://nvd.nist.gov/vuln/detail/CVE-2020-2036","https://github.com/404notf0und/CVE-Flow","https://github.com/ARPSyndicate/kenzer-templates"]},{"tag_id":"CVE-2022-2185","tag_type":"cve","title":"GitLab CE/EE - Remote Code Execution","severity":"high","actively_exploited":false,"match_field":"url_path","matched_pattern":"/users/sign_in","reference_urls":["https://gitlab.com/gitlab-com/gl-security/threatmanagement/redteam/redteam-public/cve-hash-harvester","https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-2185.json","https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-2185","https://nvd.nist.gov/vuln/detail/CVE-2022-2185","https://gitlab.com/gitlab-org/gitlab/-/issues/366088"]},{"tag_id":"CVE-2023-2825","tag_type":"cve","title":"GitLab 16.0.0 - Path Traversal","severity":"high","actively_exploited":false,"match_field":"url_path","matched_pattern":"/users/sign_in","reference_urls":["https://about.gitlab.com/releases/2023/05/23/critical-security-release-gitlab-16-0-1-released/","https://github.com/Occamsec/CVE-2023-2825","https://labs.watchtowr.com/gitlab-arbitrary-file-read-gitlab-cve-2023-2825-analysis/","https://nvd.nist.gov/vuln/detail/CVE-2023-2825","https://gitlab.com/gitlab-org/cves/-/blob/master/2023/CVE-2023-2825.json"]},{"tag_id":"CVE-2007-4556","tag_type":"cve","title":"OpenSymphony XWork/Apache Struts2 - Remote Code Execution","severity":"medium","actively_exploited":false,"match_field":"url_path","matched_pattern":"/login.action","reference_urls":["https://www.guildhab.top/?p=2326","https://nvd.nist.gov/vuln/detail/CVE-2007-4556","https://cwiki.apache.org/confluence/display/WW/S2-001","http://forums.opensymphony.com/ann.jspa?annID=54","http://issues.apache.org/struts/browse/WW-2030"]},{"tag_id":"CVE-2019-11507","tag_type":"cve","title":"Pulse Secure Pulse Connect Secure - Cross-Site Scripting (Reflected)","severity":"medium","actively_exploited":false,"match_field":"url_path","matched_pattern":"/dana-na/auth/url_default/welcome.cgi","reference_urls":["https://devco.re/blog/2019/09/02/attacking-ssl-vpn-part-3-the-golden-Pulse-Secure-ssl-vpn-rce-chain-with-Twitter-as-case-study/","https://nvd.nist.gov/vuln/detail/CVE-2019-11507"]}],"data_as_of":"2026-07-27T22:04:54.766295+00:00"}