{"ip":"172.236.28.161","total_events":120,"verdict":{"verdict":"malicious","label":"Exploit attempts observed","detail":"34 exploit-path hits","confidence":"high","network_type":"CDN","why":["34 request(s) matched a known exploit path.","Body-carrying methods (POST/PUT/PATCH/DELETE) seen: payload delivery, not just recon.","5+ hits raise confidence to high.","Not in any known-scanner range.","Sent 35,306 bytes: sustained payload delivery, not a single opportunistic request."],"engagement":{"level":"payload","label":"Sustained payload","detail":"35,306 bytes sent","bytes_sent":35306,"session_seconds":0,"persistent":false}},"first_seen":"2026-10-05T16:22:05","last_seen":"2026-10-05T16:27:33","events_24h":0,"events_7d":120,"geo":{"country_code":"GB","country_name":"United Kingdom","region":"England","city":"London","lat":51.5081,"lon":-0.1278,"asn":63949,"org":"Akamai Connected Cloud"},"source_domain":"172-236-28-161.ip.linodeusercontent.com","known_scanners":[],"scanner_tag":{"key":"linode","label":"Linode (Akamai)","category":"hosting_provider","url":"https://www.linode.com/"},"cve_matches":[{"cve_id":"CVE-2020-2551","title":"Oracle WebLogic Server - Remote Code Execution","severity":"critical","actively_exploited":true,"match_field":"url_path","matched_pattern":"/console/login/LoginForm.jsp"},{"cve_id":"CVE-2020-4427","title":"IBM Data Risk Manager - Authentication Bypass via SAML","severity":"critical","actively_exploited":true,"match_field":"url_path","matched_pattern":"/albatross/saml/idpSelection"},{"cve_id":"CVE-2020-25078","title":"D-Link DCS-2530L/DCS-2670L - Administrator Password Disclosure","severity":"high","actively_exploited":true,"match_field":"url_path","matched_pattern":"/config/getuser"},{"cve_id":"CVE-2023-23752","title":"Joomla! Webservice - Password Disclosure","severity":"medium","actively_exploited":true,"match_field":"url_path","matched_pattern":"/api/index.php/v1/config/application"},{"cve_id":"CVE-2026-21643","title":"Fortinet FortiClientEMS 7.4.4 - SQL Injection","severity":"CRITICAL","actively_exploited":true,"match_field":"url_path","matched_pattern":"/api/v1/init_consts"},{"cve_id":"CVE-2026-3055","title":"Citrix NetScaler SAML IDP - Memory Overread","severity":"CRITICAL","actively_exploited":true,"match_field":"url_path","matched_pattern":"/wsfed/passive?wctx"},{"cve_id":"CVE-2026-35616","title":"FortiClient EMS - Authentication Bypass","severity":"HIGH","actively_exploited":true,"match_field":"url_path","matched_pattern":"/api/v1/fabric_device_auth/fortigate/init"},{"cve_id":"CVE-2014-9618","title":"Netsweeper - Authentication Bypass","severity":"critical","actively_exploited":false,"match_field":"url_path","matched_pattern":"/webadmin/clientlogin"},{"cve_id":"CVE-2015-2794","title":"DotNetNuke 07.04.00 - Administration Authentication Bypass","severity":"critical","actively_exploited":false,"match_field":"url_path","matched_pattern":"/Install/InstallWizard.aspx"},{"cve_id":"CVE-2018-9995","title":"TBK DVR4104/DVR4216 Devices - Authentication Bypass","severity":"critical","actively_exploited":false,"match_field":"url_path","matched_pattern":"/device.rsp?opt=user&cmd=list"},{"cve_id":"CVE-2020-10532","title":"WatchGuard Fireware AD Helper Component - Credentials Disclosure","severity":"critical","actively_exploited":false,"match_field":"url_path","matched_pattern":"/rest/domains/list"},{"cve_id":"CVE-2020-2733","title":"JD Edwards EnterpriseOne Tools 9.2 - Information Disclosure","severity":"critical","actively_exploited":false,"match_field":"url_path","matched_pattern":"/manage/fileDownloader"},{"cve_id":"CVE-2020-5777","title":"Magento Mass Importer  <0.7.24 - Remote Auth Bypass","severity":"critical","actively_exploited":false,"match_field":"url_path","matched_pattern":"/index.php/catalogsearch/advanced/result"},{"cve_id":"CVE-2022-31814","title":"pfSense pfBlockerNG <=2.1..4_26 - OS Command Injection","severity":"critical","actively_exploited":false,"match_field":"url_path","matched_pattern":"/pfblockerng/www/index.php"},{"cve_id":"CVE-2024-25723","title":"ZenML ZenML Server - Improper Authentication","severity":"critical","actively_exploited":false,"match_field":"url_path","matched_pattern":"/api/v1/info"},{"cve_id":"CVE-2026-33032","title":"Nginx UI - Broken Access Control","severity":"critical","actively_exploited":false,"match_field":"url_path","matched_pattern":"/mcp_message"},{"cve_id":"CVE-2018-20608","title":"Imcat 4.4 - Phpinfo Configuration","severity":"high","actively_exploited":false,"match_field":"url_path","matched_pattern":"/imcat/root/tools/adbug/binfo.php"},{"cve_id":"CVE-2019-11248","title":"Debug Endpoint pprof - Exposure Detection","severity":"high","actively_exploited":false,"match_field":"url_path","matched_pattern":"/debug/pprof"},{"cve_id":"CVE-2020-9315","title":"Oracle iPlanet Web Server 7.0.x - Authentication Bypass","severity":"high","actively_exploited":false,"match_field":"url_path","matched_pattern":"/admingui/version/serverConfigurationsGeneral"},{"cve_id":"CVE-2021-37305","title":"Jeecg Boot <= 2.4.5 - Sensitive Information Disclosure","severity":"high","actively_exploited":false,"match_field":"url_path","matched_pattern":"/jeecg-boot/sys/user/querySysUser"},{"cve_id":"CVE-2022-1392","title":"WordPress Videos sync PDF <=1.7.4 - Local File Inclusion","severity":"high","actively_exploited":false,"match_field":"url_path","matched_pattern":"/wp-content/plugins/video-synchro-pdf/reglages/Menu_Plugins/tout.php"},{"cve_id":"CVE-2022-1711","title":"draw.io < 18.0.5 - Server Side Request Forgery (SSRF)","severity":"high","actively_exploited":false,"match_field":"url_path","matched_pattern":"/proxy?url=http:"},{"cve_id":"CVE-2022-2379","title":"WordPress Easy Student Results <=2.2.8 - Improper Authorization","severity":"high","actively_exploited":false,"match_field":"url_path","matched_pattern":"/wp-json/rps_result/v1/route/search_student"},{"cve_id":"CVE-2022-24288","title":"Apache Airflow OS Command Injection","severity":"high","actively_exploited":false,"match_field":"url_path","matched_pattern":"/admin/airflow/code"},{"cve_id":"CVE-2022-2551","title":"WordPress Duplicator <1.4.7 - Authentication Bypass","severity":"high","actively_exploited":false,"match_field":"url_path","matched_pattern":"/wp-content/dup-installer/main.installer.php"},{"cve_id":"CVE-2022-34046","title":"WAVLINK WN533A8 - Improper Access Control","severity":"high","actively_exploited":false,"match_field":"url_path","matched_pattern":"/sysinit.shtml"},{"cve_id":"CVE-2023-4168","title":"Adlisting Classified Ads 2.14.0 - Information Disclosure","severity":"high","actively_exploited":false,"match_field":"url_path","matched_pattern":"/ad-list-search"},{"cve_id":"CVE-2024-49757","title":"Zitadel - User Registration Bypass","severity":"high","actively_exploited":false,"match_field":"url_path","matched_pattern":"/ui/login/register"},{"cve_id":"CVE-2026-1207","title":"Django RasterField - SQL Injection","severity":"high","actively_exploited":false,"match_field":"url_path","matched_pattern":"/api/raster/search/?band=1)%20AND%201=CAST((SELECT%20version())%20AS%20INT)--"},{"cve_id":"CVE-2026-1557","title":"WP Responsive Images <= 1.0 - Arbitrary File Read","severity":"high","actively_exploited":false,"match_field":"url_path","matched_pattern":"/wp-content/plugins/wp-responsive-images/image_handler.php?src=/wp-config.php"},{"cve_id":"CVE-2026-21859","title":"Mailpit < 1.28.3 - Server-Side Request Forgery","severity":"high","actively_exploited":false,"match_field":"url_path","matched_pattern":"/proxy?url=http://127.0.0.1:8025/api/v1/info"},{"cve_id":"CVE-2026-23550","title":"Modular DS - Broken Access Control","severity":"high","actively_exploited":false,"match_field":"url_path","matched_pattern":"/api/modular-connector/login"},{"cve_id":"CVE-2026-25892","title":"Adminer 4.6.2 - 5.4.1 Unauthenticated Persistent DoS","severity":"high","actively_exploited":false,"match_field":"url_path","matched_pattern":"/adminer.php"},{"cve_id":"CVE-2005-2428","title":"Lotus Domino R5 and R6 WebMail - Information Disclosure","severity":"medium","actively_exploited":false,"match_field":"url_path","matched_pattern":"/names.nsf/People"},{"cve_id":"CVE-2015-8399","title":"Atlassian Confluence <5.8.17 - Information Disclosure","severity":"medium","actively_exploited":false,"match_field":"url_path","matched_pattern":"/spaces/viewdefaultdecorator.action"},{"cve_id":"CVE-2018-10245","title":"AWStats <= 7.5 - Full Path Disclosure","severity":"medium","actively_exploited":false,"match_field":"url_path","matched_pattern":"/awstats/awstats.pl"},{"cve_id":"CVE-2018-11409","title":"Splunk <=7.0.1 - Information Disclosure","severity":"medium","actively_exploited":false,"match_field":"url_path","matched_pattern":"/__raw/services/server/info/server-info"},{"cve_id":"CVE-2018-16670","title":"CirCarLife <4.3 - Improper Authentication","severity":"medium","actively_exploited":false,"match_field":"url_path","matched_pattern":"/services/user/values.xml"},{"cve_id":"CVE-2019-3401","title":"Atlassian Jira <7.13.3/8.0.0-8.1.1 - Incorrect Authorization","severity":"medium","actively_exploited":false,"match_field":"url_path","matched_pattern":"/secure/ManageFilters.jspa?filter=popular&filterView=popular"},{"cve_id":"CVE-2019-3403","title":"Jira - Incorrect Authorization","severity":"medium","actively_exploited":false,"match_field":"url_path","matched_pattern":"/rest/api/2/user/picker"},{"cve_id":"CVE-2019-8449","title":"Jira <8.4.0 - Information Disclosure","severity":"medium","actively_exploited":false,"match_field":"url_path","matched_pattern":"/rest/api/latest/groupuserpicker"},{"cve_id":"CVE-2020-20285","title":"ZZcms - Cross-Site Scripting","severity":"medium","actively_exploited":false,"match_field":"url_path","matched_pattern":"/user/login.php"},{"cve_id":"CVE-2021-21745","title":"ZTE MF971R - Referer authentication bypass","severity":"medium","actively_exploited":false,"match_field":"url_path","matched_pattern":"/goform/goform_get_cmd_process?cmd=psw_fail_num_str"},{"cve_id":"CVE-2021-24997","title":"WordPress Guppy <=1.1 - Information Disclosure","severity":"medium","actively_exploited":false,"match_field":"url_path","matched_pattern":"/wp-json/guppy/v2/load-guppy-users"},{"cve_id":"CVE-2022-24819","title":"XWiki < 12.10.11, 13.4.4 & 13.9-rc-1 - Information Disclosure","severity":"medium","actively_exploited":false,"match_field":"url_path","matched_pattern":"/bin/login/XWikiLogin"},{"cve_id":"CVE-2022-26159","title":"Ametys CMS Information Disclosure","severity":"medium","actively_exploited":false,"match_field":"url_path","matched_pattern":"/plugins/web/service/search/auto-completion/domain/en.xml"},{"cve_id":"CVE-2022-31260","title":"ResourceSpace - Metadata Export","severity":"medium","actively_exploited":false,"match_field":"url_path","matched_pattern":"/pages/csv_export_results_metadata.php"},{"cve_id":"CVE-2022-35416","title":"H3C SSL VPN <=2022-07-10 - Cross-Site Scripting","severity":"medium","actively_exploited":false,"match_field":"url_path","matched_pattern":"/wnm/login/login.json"},{"cve_id":"CVE-2023-35155","title":"XWiki - Cross-Site Scripting","severity":"medium","actively_exploited":false,"match_field":"url_path","matched_pattern":"/xwiki/bin/view/Main"},{"cve_id":"CVE-2023-50720","title":"XWiki < 4.10.15 - Email Disclosure","severity":"medium","actively_exploited":false,"match_field":"url_path","matched_pattern":"/bin/view/Main/Search"},{"cve_id":"CVE-2024-5230","title":"FleetCart 4.1.1 - Information Disclosure","severity":"medium","actively_exploited":false,"match_field":"url_path","matched_pattern":"/en/products"},{"cve_id":"CVE-2024-54763","title":"ipTIME A2004 - Unauthorized Access","severity":"medium","actively_exploited":false,"match_field":"url_path","matched_pattern":"/login/hostinfo.cgi"},{"cve_id":"CVE-2024-54764","title":"ipTIME A2004 - Unauthorized Access","severity":"medium","actively_exploited":false,"match_field":"url_path","matched_pattern":"/login/hostinfo2.cgi"},{"cve_id":"CVE-2024-6188","title":"TrakSYS 11.x.x - Sensitive Data Exposure","severity":"medium","actively_exploited":false,"match_field":"url_path","matched_pattern":"/TS/export/pagedefinition"},{"cve_id":"CVE-2024-9617","title":"Danswer - Insecure Direct Object Reference","severity":"medium","actively_exploited":false,"match_field":"url_path","matched_pattern":"/api/chat/get-chat-session/1"},{"cve_id":"CVE-2026-1277","title":"URL Shortify <= 1.12.1 - Open Redirect","severity":"medium","actively_exploited":false,"match_field":"url_path","matched_pattern":"/wp-admin/admin-ajax.php?action=heartbeat&kc_us_dismiss_admin_notice=1&option_name=bfcm_2025_offer&redirect_to=https://i"},{"cve_id":"CVE-2026-24128","title":"XWiki Platform Distribution Flavor Main - Cross-Site Scripting","severity":"medium","actively_exploited":false,"match_field":"url_path","matched_pattern":"/xwiki/bin/view/XWiki/Main?xpage=distribution&extensionSection=progress&extensionId=org.xwiki.platform%3Axwiki-platform-"},{"cve_id":"CVE-2026-1581","title":"wpForo Forum <= 2.4.14 - SQL Injection","severity":"CRITICAL","actively_exploited":false,"match_field":"url_path","matched_pattern":"/community/recent/?wpfob=(SELECT/**/1/**/FROM/**/(SELECT/**/SLEEP(8))a)"},{"cve_id":"CVE-2026-21445","title":"Langflow - Broken Access Control","severity":"CRITICAL","actively_exploited":false,"match_field":"url_path","matched_pattern":"/api/v1/monitor/messages"},{"cve_id":"CVE-2026-4020","title":"Gravity SMTP WordPress Plugin - Sensitive Information Exposure","severity":"HIGH","actively_exploited":false,"match_field":"url_path","matched_pattern":"/wp-json/gravitysmtp/v1/tests/mock-data?page=gravitysmtp-settings"}],"malware":[],"udp":null,"top_ports":[{"port":8443,"proto":"tcp","label":"HTTPS-alt","count":120}],"fingerprints":{"ssh_hassh":[],"tls_ja4":[],"tls_client_hello":"","tls_ja3":[],"http_akin":["b11cun050_08040013_2619b3ac","b11cun040_00040013_608dab68","b11cuq060_00050813_95cc9d02","b11cun060_0004001f_eefe5210","b11cun040_00060011_0e46e402"]},"fingerprint_peers":{"b11cun040_00040013_608dab68":4393,"b11cuq060_00050813_95cc9d02":46,"b11cun060_0004001f_eefe5210":9,"b11cun040_00060011_0e46e402":10,"b11cun050_08040013_2619b3ac":4},"akin_families":{"b11cun050_08040013_2619b3ac":{"head":"b11cun050_08040013_2619b3ac","shapes":4,"ips":4},"b11cuq060_00050813_95cc9d02":{"head":"b11cuq060_00050813_95cc9d02","shapes":6,"ips":46},"b11cun060_0004001f_eefe5210":{"head":"b11cun060_0004001f_eefe5210","shapes":2,"ips":9}},"user_agents":["Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/106.0.0.0 Safari/537.36","Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:140.0) Gecko/20100101 Firefox/140.0","Mozilla/5.0 (Macintosh, Intel Mac OS X 10_15_7) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/16.1 Safari/605.1.15","Mozilla/5.0 (X11; Linux i686) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/140.0.0.0 Safari/537.36","Mozilla/5.0 (Debian; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/129.0.0.0 Safari/537.36","Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/130.0.0.0 Safari/537.36","Mozilla/5.0 (ZZ; Linux i686) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/128.0.0.0 Safari/537.36","Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.4.1 Safari/605.1.22"],"timeline":[{"date":"2026-10-05","count":120}],"recent_events":[{"timestamp":"2026-10-05T16:27:33","port":8443,"proto":"tcp","app_proto":"","app_protocol":"http","host":"<HONEYPOT>","headers":"{\"accept\":\"*/*\",\"accept-encoding\":\"gzip\",\"accept-language\":\"en\",\"connection\":\"close\",\"host\":\"<HONEYPOT>:8443\",\"user-agent\":\"Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_6) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/15.2 Safari/605.1.15\"}","body":"","sni":"","tls_cipher":"","tls_version":"","alpn":[],"url_path":"/wp-content/dup-installer/main.installer.php?is_daws=1","summary":"","payload_hex":"474554202f77702d636f6e74656e742f6475702d696e7374616c6c65722f6d61696e2e696e7374616c6c65722e7068703f69735f646177733d3120485454502f312e310d0a486f73743a20<HONEYPOT>3a383434330d0a557365722d4167656e743a204d6f7a696c6c612f352e3020284d6163696e746f73683b20496e74656c204d6163204f5320582031305f31355f3629204170706c655765624b69742f3630352e312e313520284b48544d4c2c206c696b65204765636b6f292056657273696f6e2f31352e32205361666172692f3630352e312e31350d0a436f6e6e656374696f6e3a20636c6f73650d0a4163636570743a202a2f2a0d0a4163636570742d4c616e67756167653a20656e0d0a4163636570742d456e636f64696e673a20677a69700d0a0d0a","method":"GET","user_agent":"Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_6) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/15.2 Safari/605.1.15","ja3":"","session":"123f3d84-7e5b-4831-8020-78561ae2d9e7","seq":1,"duration_ms":100,"bytes_in":304,"bytes_out":79},{"timestamp":"2026-10-05T16:27:32","port":8443,"proto":"tcp","app_proto":"","app_protocol":"http","host":"<HONEYPOT>","headers":"{\"accept\":\"*/*\",\"accept-encoding\":\"gzip\",\"accept-language\":\"en\",\"connection\":\"close\",\"host\":\"<HONEYPOT>:8443\",\"user-agent\":\"Mozilla/5.0 (ZZ; Linux i686) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36\"}","body":"","sni":"","tls_cipher":"","tls_version":"","alpn":[],"url_path":"/wp-content/backups-dup-lite/dup-installer/main.installer.php?is_daws=1","summary":"","payload_hex":"474554202f77702d636f6e74656e742f6261636b7570732d6475702d6c6974652f6475702d696e7374616c6c65722f6d61696e2e696e7374616c6c65722e7068703f69735f646177733d3120485454502f312e310d0a486f73743a20<HONEYPOT>3a383434330d0a557365722d4167656e743a204d6f7a696c6c612f352e3020285a5a3b204c696e7578206936383629204170706c655765624b69742f3533372e333620284b48544d4c2c206c696b65204765636b6f29204368726f6d652f3133342e302e302e30205361666172692f3533372e33360d0a436f6e6e656374696f6e3a20636c6f73650d0a4163636570743a202a2f2a0d0a4163636570742d4c616e67756167653a20656e0d0a4163636570742d456e636f64696e673a20677a69700d0a0d0a","method":"GET","user_agent":"Mozilla/5.0 (ZZ; Linux i686) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36","ja3":"","session":"8806d4f7-29df-44e8-8c94-17934cd3146c","seq":1,"duration_ms":100,"bytes_in":302,"bytes_out":79},{"timestamp":"2026-10-05T16:27:19","port":8443,"proto":"tcp","app_proto":"","app_protocol":"http","host":"<HONEYPOT>","headers":"{\"accept\":\"*/*\",\"accept-encoding\":\"gzip\",\"accept-language\":\"en\",\"connection\":\"close\",\"host\":\"<HONEYPOT>:8443\",\"user-agent\":\"Mozilla/5.0 (X11; Linux x86_64; rv:138.0) Gecko/20100101 Firefox/138.0\"}","body":"","sni":"","tls_cipher":"","tls_version":"","alpn":[],"url_path":"/login","summary":"","payload_hex":"474554202f6c6f67696e20485454502f312e310d0a486f73743a20<HONEYPOT>3a383434330d0a557365722d4167656e743a204d6f7a696c6c612f352e3020285831313b204c696e7578207838365f36343b2072763a3133382e3029204765636b6f2f32303130303130312046697265666f782f3133382e300d0a436f6e6e656374696f6e3a20636c6f73650d0a4163636570743a202a2f2a0d0a4163636570742d4c616e67756167653a20656e0d0a4163636570742d456e636f64696e673a20677a69700d0a0d0a","method":"GET","user_agent":"Mozilla/5.0 (X11; Linux x86_64; rv:138.0) Gecko/20100101 Firefox/138.0","ja3":"","session":"f1fa1386-1d02-48a4-8a8d-142321a26f62","seq":1,"duration_ms":100,"bytes_in":209,"bytes_out":79},{"timestamp":"2026-10-05T16:27:19","port":8443,"proto":"tcp","app_proto":"","app_protocol":"http","host":"<HONEYPOT>","headers":"{\"accept-encoding\":\"gzip\",\"connection\":\"close\",\"host\":\"<HONEYPOT>:8443\",\"user-agent\":\"Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:84.0) Gecko/20100101 Firefox/84.0\"}","body":"","sni":"","tls_cipher":"","tls_version":"","alpn":[],"url_path":"/wsfed/passive?wctx","summary":"","payload_hex":"474554202f77736665642f706173736976653f7763747820485454502f312e310d0a486f73743a20<HONEYPOT>3a383434330d0a557365722d4167656e743a204d6f7a696c6c612f352e30202857696e646f7773204e542031302e303b2057696e36343b207836343b2072763a38342e3029204765636b6f2f32303130303130312046697265666f782f38342e300d0a436f6e6e656374696f6e3a20636c6f73650d0a4163636570742d456e636f64696e673a20677a69700d0a0d0a","method":"GET","user_agent":"Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:84.0) Gecko/20100101 Firefox/84.0","ja3":"","session":"b35f3624-58e6-4f04-a5be-adeb90d1833b","seq":1,"duration_ms":100,"bytes_in":196,"bytes_out":79},{"timestamp":"2026-10-05T16:27:15","port":8443,"proto":"tcp","app_proto":"","app_protocol":"http","host":"<HONEYPOT>","headers":"{\"accept-encoding\":\"gzip\",\"connection\":\"close\",\"content-length\":\"510\",\"content-type\":\"application/x-www-form-urlencoded\",\"host\":\"<HONEYPOT>:8443\",\"user-agent\":\"Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36\"}","body":"SAMLRequest=PHNhbWxwOkF1dGhuUmVxdWVzdCB4bWxuczpzYW1scD0idXJuOm9hc2lzOm5hbWVzOnRjOlNBTUw6Mi4wOnByb3RvY29sIiANCnhtbG5zOnNhbWw9InVybjpvYXNpczpuYW1lczp0YzpTQU1MOjIuMDphc3NlcnRpb24iICANCklEPSJfMSINClZlcnNpb249IjIuMCIgUHJvdmlkZXJOYW1lPSJteSBwcm92aWRlciIgDQpEZXN0aW5hdGlvbj0iaHR0cDovL3dhdGNodG93ci9zYW1sLnBocCIgDQpQcm90b2NvbEJpbmRpbmc9InVybjpvYXNpczpuYW1lczp0YzpTQU1MOjIuMDpiaW5kaW5nczpIVFRQLVBPU1QiIA0KPg0KICA8c2FtbDpJc3N1ZXI%2BaHR0cDovL3dhdGNodG93ci9zYW1sLnBocDwvc2FtbDpJc3N1ZXI%2BDQo8L3NhbWxwOkF1dGhuUmVxdWVzdD4%3D","sni":"","tls_cipher":"","tls_version":"","alpn":[],"url_path":"/saml/login","summary":"","payload_hex":"504f5354202f73616d6c2f6c6f67696e20485454502f312e310d0a486f73743a20<HONEYPOT>3a383434330d0a557365722d4167656e743a204d6f7a696c6c612f352e3020285831313b204c696e7578207838365f363429204170706c655765624b69742f3533372e333620284b48544d4c2c206c696b65204765636b6f29204368726f6d652f3131372e302e302e30205361666172692f3533372e33360d0a436f6e6e656374696f6e3a20636c6f73650d0a436f6e74656e742d4c656e6774683a203531300d0a4163636570742d456e636f64696e673a20677a69700d0a436f6e74656e742d547970653a206170706c69636174696f6e2f782d7777772d666f726d2d75726c656e636f6465640d0a0d0a53414d4c526571756573743d50484e68625778774f6b463164476875556d56786457567a6443423462577875637a707a595731736344306964584a754f6d396863326c7a4f6d35686257567a4f6e526a4f6c4e42545577364d6934774f6e427962335276593239734969414e436e68746247357a4f6e4e6862577739496e5679626a707659584e70637a70755957316c637a7030597a70545155314d4f6a49754d44706863334e6c636e5270623234694943414e436b6c4550534a664d53494e436c5a6c636e4e7062323439496a49754d43496755484a76646d6c6b5a584a4f5957316c50534a7465534277636d39326157526c63694967445170455a584e306157356864476c76626a30696148523063446f764c33646864474e6f644739336369397a595731734c6e426f6343496744517051636d393062324e7662454a70626d5270626d6339496e5679626a707659584e70637a70755957316c637a7030597a70545155314d4f6a49754d4470696157356b6157356e637a7049564652514c564250553151694941304b5067304b49434138633246746244704a63334e315a58492532426148523063446f764c33646864474e6f644739336369397a595731734c6e426f63447776633246746244704a63334e315a584925324244516f384c334e68625778774f6b463164476875556d56786457567a644434253344","method":"POST","user_agent":"Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36","ja3":"","session":"afdeb163-80e3-47bc-ae5c-df4305c4d31b","seq":1,"duration_ms":100,"bytes_in":792,"bytes_out":79},{"timestamp":"2026-10-05T16:27:14","port":8443,"proto":"tcp","app_proto":"","app_protocol":"http","host":"<HONEYPOT>","headers":"{\"accept\":\"*/*\",\"accept-encoding\":\"gzip\",\"accept-language\":\"en\",\"connection\":\"close\",\"host\":\"<HONEYPOT>:8443\",\"user-agent\":\"Mozilla/5.0 (Windows NT 6.2; rv:128.12) Gecko/20100101 Firefox/128.12\"}","body":"","sni":"","tls_cipher":"","tls_version":"","alpn":[],"url_path":"/","summary":"","payload_hex":"474554202f20485454502f312e310d0a486f73743a20<HONEYPOT>3a383434330d0a557365722d4167656e743a204d6f7a696c6c612f352e30202857696e646f7773204e5420362e323b2072763a3132382e313229204765636b6f2f32303130303130312046697265666f782f3132382e31320d0a436f6e6e656374696f6e3a20636c6f73650d0a4163636570743a202a2f2a0d0a4163636570742d4c616e67756167653a20656e0d0a4163636570742d456e636f64696e673a20677a69700d0a0d0a","method":"GET","user_agent":"Mozilla/5.0 (Windows NT 6.2; rv:128.12) Gecko/20100101 Firefox/128.12","ja3":"","session":"9de8d59f-29e7-4ff8-895f-4597f8013c4a","seq":1,"duration_ms":100,"bytes_in":203,"bytes_out":79},{"timestamp":"2026-10-05T16:26:46","port":8443,"proto":"tcp","app_proto":"","app_protocol":"http","host":"<HONEYPOT>","headers":"{\"accept\":\"*/*\",\"accept-encoding\":\"gzip\",\"accept-language\":\"en\",\"connection\":\"close\",\"host\":\"<HONEYPOT>:8443\",\"user-agent\":\"Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/79.0.3945.79 Safari/537.36\"}","body":"","sni":"","tls_cipher":"","tls_version":"","alpn":[],"url_path":"/login/hostinfo2.cgi","summary":"","payload_hex":"474554202f6c6f67696e2f686f7374696e666f322e63676920485454502f312e310d0a486f73743a20<HONEYPOT>3a383434330d0a557365722d4167656e743a204d6f7a696c6c612f352e30202857696e646f7773204e542031302e303b2057696e36343b2078363429204170706c655765624b69742f3533372e333620284b48544d4c2c206c696b65204765636b6f29204368726f6d652f37392e302e333934352e3739205361666172692f3533372e33360d0a436f6e6e656374696f6e3a20636c6f73650d0a4163636570743a202a2f2a0d0a4163636570742d4c616e67756167653a20656e0d0a4163636570742d456e636f64696e673a20677a69700d0a0d0a","method":"GET","user_agent":"Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/79.0.3945.79 Safari/537.36","ja3":"","session":"db921d46-036f-4157-9d21-02eea061ab69","seq":1,"duration_ms":100,"bytes_in":267,"bytes_out":79},{"timestamp":"2026-10-05T16:26:46","port":8443,"proto":"tcp","app_proto":"","app_protocol":"http","host":"<HONEYPOT>","headers":"{\"accept\":\"*/*\",\"accept-encoding\":\"gzip\",\"accept-language\":\"en\",\"connection\":\"close\",\"host\":\"<HONEYPOT>:8443\",\"user-agent\":\"Mozilla/5.0 (SS; Linux i686) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/130.0.0.0 Safari/537.36\"}","body":"","sni":"","tls_cipher":"","tls_version":"","alpn":[],"url_path":"/names.nsf/People?OpenView","summary":"","payload_hex":"474554202f6e616d65732e6e73662f50656f706c653f4f70656e5669657720485454502f312e310d0a486f73743a20<HONEYPOT>3a383434330d0a557365722d4167656e743a204d6f7a696c6c612f352e30202853533b204c696e7578206936383629204170706c655765624b69742f3533372e333620284b48544d4c2c206c696b65204765636b6f29204368726f6d652f3133302e302e302e30205361666172692f3533372e33360d0a436f6e6e656374696f6e3a20636c6f73650d0a4163636570743a202a2f2a0d0a4163636570742d4c616e67756167653a20656e0d0a4163636570742d456e636f64696e673a20677a69700d0a0d0a","method":"GET","user_agent":"Mozilla/5.0 (SS; Linux i686) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/130.0.0.0 Safari/537.36","ja3":"","session":"2273ba26-b8ee-46f6-97ba-0b561dccc6c9","seq":1,"duration_ms":101,"bytes_in":257,"bytes_out":79},{"timestamp":"2026-10-05T16:26:46","port":8443,"proto":"tcp","app_proto":"","app_protocol":"http","host":"<HONEYPOT>","headers":"{\"accept\":\"*/*\",\"accept-encoding\":\"gzip\",\"accept-language\":\"en\",\"connection\":\"close\",\"host\":\"<HONEYPOT>:8443\",\"user-agent\":\"Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36\"}","body":"","sni":"","tls_cipher":"","tls_version":"","alpn":[],"url_path":"/info/dir?/","summary":"","payload_hex":"474554202f696e666f2f6469723f2f20485454502f312e310d0a486f73743a20<HONEYPOT>3a383434330d0a557365722d4167656e743a204d6f7a696c6c612f352e3020284d6163696e746f73683b20496e74656c204d6163204f5320582031305f31355f3729204170706c655765624b69742f3533372e333620284b48544d4c2c206c696b65204765636b6f29204368726f6d652f3133342e302e302e30205361666172692f3533372e33360d0a436f6e6e656374696f6e3a20636c6f73650d0a4163636570743a202a2f2a0d0a4163636570742d4c616e67756167653a20656e0d0a4163636570742d456e636f64696e673a20677a69700d0a0d0a","method":"GET","user_agent":"Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36","ja3":"","session":"df62dd65-ff85-42b3-9aa8-d9efdba99bbc","seq":1,"duration_ms":101,"bytes_in":261,"bytes_out":79},{"timestamp":"2026-10-05T16:26:46","port":8443,"proto":"tcp","app_proto":"","app_protocol":"http","host":"<HONEYPOT>","headers":"{\"accept\":\"*/*\",\"accept-encoding\":\"gzip\",\"accept-language\":\"en\",\"connection\":\"close\",\"host\":\"<HONEYPOT>:8443\",\"user-agent\":\"Mozilla/5.0 (Macintosh; Intel Mac OS X 10_13_6) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/11.1.2 Safari/605.1.15\"}","body":"","sni":"","tls_cipher":"","tls_version":"","alpn":[],"url_path":"/login?redirect=%2F","summary":"","payload_hex":"474554202f6c6f67696e3f72656469726563743d25324620485454502f312e310d0a486f73743a20<HONEYPOT>3a383434330d0a557365722d4167656e743a204d6f7a696c6c612f352e3020284d6163696e746f73683b20496e74656c204d6163204f5320582031305f31335f3629204170706c655765624b69742f3630352e312e313520284b48544d4c2c206c696b65204765636b6f292056657273696f6e2f31312e312e32205361666172692f3630352e312e31350d0a436f6e6e656374696f6e3a20636c6f73650d0a4163636570743a202a2f2a0d0a4163636570742d4c616e67756167653a20656e0d0a4163636570742d456e636f64696e673a20677a69700d0a0d0a","method":"GET","user_agent":"Mozilla/5.0 (Macintosh; Intel Mac OS X 10_13_6) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/11.1.2 Safari/605.1.15","ja3":"","session":"1fd09018-3dec-46c6-b1db-ceedc288d23c","seq":1,"duration_ms":100,"bytes_in":271,"bytes_out":79}],"http_methods":[{"method":"GET","count":114},{"method":"POST","count":4},{"method":"HEAD","count":2}],"distinct_ports_total":1,"top_paths":[{"path":"/","count":5,"ports":1},{"path":"/api/v1/init_consts","count":2,"ports":1},{"path":"/login","count":2,"ports":1},{"path":"/__","count":2,"ports":1},{"path":"/api/v1/fabric_device_auth/fortigate/init","count":2,"ports":1},{"path":"/__raw/services/server/info/server-info?output_mode=json","count":1,"ports":1},{"path":"/cs/Satellite?pagename=OpenMarket/Xcelerate/Admin/WebReferences","count":1,"ports":1},{"path":"/adminer/","count":1,"ports":1},{"path":"/info/dir?/","count":1,"ports":1},{"path":"/wp-login.php","count":1,"ports":1},{"path":"/debug/pprof/","count":1,"ports":1},{"path":"/pentaho/Login","count":1,"ports":1},{"path":"/aj.html?a=devi","count":1,"ports":1},{"path":"/api/backup","count":1,"ports":1},{"path":"/login?next=/","count":1,"ports":1}],"distinct_paths_total":112,"top_snis":[],"top_hosts":[],"top_alpns":[],"banners":[],"credentials":[],"header_profile":{"signature":["Accept","Accept-Encoding","Accept-Language","Connection","Host","User-Agent"],"representative":[{"name":"Accept","value":"*/*","notable":false},{"name":"Accept-Encoding","value":"gzip","notable":false},{"name":"Accept-Language","value":"en","notable":false},{"name":"Connection","value":"close","notable":false},{"name":"Host","value":"<HONEYPOT>:8443","notable":false},{"name":"User-Agent","value":"Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_6) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/15.2 Safari/605.1.15","notable":false}],"distinct_sets":3,"events_with_headers":10},"tags":[{"tag_id":"CVE-2020-2551","tag_type":"cve","title":"Oracle WebLogic Server - Remote Code Execution","severity":"critical","actively_exploited":true,"match_field":"url_path","matched_pattern":"/console/login/LoginForm.jsp","reference_urls":["https://github.com/hktalent/CVE-2020-2551","https://nvd.nist.gov/vuln/detail/CVE-2020-2551","https://www.oracle.com/security-alerts/cpujan2020.html","https://github.com/neilzhang1/Chinese-Charts","https://github.com/pjgmonteiro/Pentest-tools"]},{"tag_id":"CVE-2020-4427","tag_type":"cve","title":"IBM Data Risk Manager - Authentication Bypass via SAML","severity":"critical","actively_exploited":true,"match_field":"url_path","matched_pattern":"/albatross/saml/idpSelection","reference_urls":["https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/linux/http/ibm_drm_rce.rb","https://seclists.org/fulldisclosure/2020/Apr/33","https://www.ibm.com/support/pages/node/6206875","https://nvd.nist.gov/vuln/detail/CVE-2020-4427"]},{"tag_id":"CVE-2020-25078","tag_type":"cve","title":"D-Link DCS-2530L/DCS-2670L - Administrator Password Disclosure","severity":"high","actively_exploited":true,"match_field":"url_path","matched_pattern":"/config/getuser","reference_urls":["https://supportannouncement.us.dlink.com/announcement/publication.aspx?name=SAP10180","https://twitter.com/Dogonsecurity/status/1273251236167516161","https://nvd.nist.gov/vuln/detail/CVE-2020-25078","https://github.com/pen4uin/vulnerability-research-list","https://github.com/ArrestX/--POC"]},{"tag_id":"CVE-2023-23752","tag_type":"cve","title":"Joomla! Webservice - Password Disclosure","severity":"medium","actively_exploited":true,"match_field":"url_path","matched_pattern":"/api/index.php/v1/config/application","reference_urls":["https://unsafe.sh/go-149780.html","https://twitter.com/gov_hack/status/1626471960141238272/photo/1","https://developer.joomla.org/security-centre/894-20230201-core-improper-access-check-in-webservice-endpoints.html","https://nvd.nist.gov/vuln/detail/CVE-2023-23552","https://github.com/20142995/pocsuite3"]},{"tag_id":"CVE-2026-21643","tag_type":"cve","title":"Fortinet FortiClientEMS 7.4.4 - SQL Injection","severity":"CRITICAL","actively_exploited":true,"match_field":"url_path","matched_pattern":"/api/v1/init_consts","reference_urls":[]},{"tag_id":"CVE-2026-3055","tag_type":"cve","title":"Citrix NetScaler SAML IDP - Memory Overread","severity":"CRITICAL","actively_exploited":true,"match_field":"url_path","matched_pattern":"/wsfed/passive?wctx","reference_urls":[]},{"tag_id":"CVE-2026-35616","tag_type":"cve","title":"FortiClient EMS - Authentication Bypass","severity":"HIGH","actively_exploited":true,"match_field":"url_path","matched_pattern":"/api/v1/fabric_device_auth/fortigate/init","reference_urls":[]},{"tag_id":"CVE-2014-9618","tag_type":"cve","title":"Netsweeper - Authentication Bypass","severity":"critical","actively_exploited":false,"match_field":"url_path","matched_pattern":"/webadmin/clientlogin","reference_urls":["https://packetstormsecurity.com/files/download/133034/netsweeper-issues.tgz","https://nvd.nist.gov/vuln/detail/CVE-2014-9618","https://www.exploit-db.com/exploits/37933/","http://packetstormsecurity.com/files/133034/Netsweeper-Bypass-XSS-Redirection-SQL-Injection-Execution.html","https://github.com/ARPSyndicate/kenzer-templates"]},{"tag_id":"CVE-2015-2794","tag_type":"cve","title":"DotNetNuke 07.04.00 - Administration Authentication Bypass","severity":"critical","actively_exploited":false,"match_field":"url_path","matched_pattern":"/Install/InstallWizard.aspx","reference_urls":["https://nvd.nist.gov/vuln/detail/CVE-2015-2794","https://www.exploit-db.com/exploits/39777","http://www.dnnsoftware.com/community-blog/cid/155198/workaround-for-potential-security-issue","http://www.dnnsoftware.com/community/security/security-center","https://dotnetnuke.codeplex.com/releases/view/615317"]},{"tag_id":"CVE-2018-9995","tag_type":"cve","title":"TBK DVR4104/DVR4216 Devices - Authentication Bypass","severity":"critical","actively_exploited":false,"match_field":"url_path","matched_pattern":"/device.rsp?opt=user&cmd=list","reference_urls":["https://www.exploit-db.com/exploits/44577/","http://misteralfa-hack.blogspot.cl/2018/04/tbk-vision-dvr-login-bypass.html","http://misteralfa-hack.blogspot.cl/2018/04/update-dvr-login-bypass-cve-2018-9995.html","https://www.bleepingcomputer.com/news/security/new-hacking-tool-lets-users-access-a-bunch-of-dvrs-and-their-video-feeds/","https://nvd.nist.gov/vuln/detail/CVE-2018-9995"]},{"tag_id":"CVE-2020-10532","tag_type":"cve","title":"WatchGuard Fireware AD Helper Component - Credentials Disclosure","severity":"critical","actively_exploited":false,"match_field":"url_path","matched_pattern":"/rest/domains/list","reference_urls":["https://nvd.nist.gov/vuln/detail/CVE-2020-10532","https://www.exploit-db.com/exploits/48203","https://www.watchguard.com/wgrd-blog/tdr-ad-helper-credential-disclosure-vulnerability"]},{"tag_id":"CVE-2020-2733","tag_type":"cve","title":"JD Edwards EnterpriseOne Tools 9.2 - Information Disclosure","severity":"critical","actively_exploited":false,"match_field":"url_path","matched_pattern":"/manage/fileDownloader","reference_urls":["https://redrays.io/cve-2020-2733-jd-edwards/","https://www.oracle.com/security-alerts/cpuapr2020.html","https://nvd.nist.gov/vuln/detail/CVE-2020-2733","https://github.com/ARPSyndicate/cvemon","https://github.com/ARPSyndicate/kenzer-templates"]},{"tag_id":"CVE-2020-5777","tag_type":"cve","title":"Magento Mass Importer  <0.7.24 - Remote Auth Bypass","severity":"critical","actively_exploited":false,"match_field":"url_path","matched_pattern":"/index.php/catalogsearch/advanced/result","reference_urls":["https://github.com/dweeves/magmi-git/blob/18bd9ec905c90bfc9eaed0c2bf2d3525002e33b9/magmi/inc/magmi_auth.php#L35","https://nvd.nist.gov/vuln/detail/CVE-2020-5777","https://www.tenable.com/security/research/tra-2020-51","https://github.com/404notf0und/CVE-Flow","https://github.com/ARPSyndicate/cvemon"]},{"tag_id":"CVE-2022-31814","tag_type":"cve","title":"pfSense pfBlockerNG <=2.1..4_26 - OS Command Injection","severity":"critical","actively_exploited":false,"match_field":"url_path","matched_pattern":"/pfblockerng/www/index.php","reference_urls":["https://www.ihteam.net/advisory/pfblockerng-unauth-rce-vulnerability/","https://docs.netgate.com/pfsense/en/latest/packages/pfblocker.html","https://github.com/EvergreenCartoons/SenselessViolence","https://nvd.nist.gov/vuln/detail/CVE-2022-31814","http://packetstormsecurity.com/files/171123/pfBlockerNG-2.1.4_26-Remote-Code-Execution.html"]},{"tag_id":"CVE-2024-25723","tag_type":"cve","title":"ZenML ZenML Server - Improper Authentication","severity":"critical","actively_exploited":false,"match_field":"url_path","matched_pattern":"/api/v1/info","reference_urls":["https://www.zenml.io/blog/critical-security-update-for-zenml-users","https://github.com/zenml-io/zenml","https://github.com/zenml-io/zenml/compare/0.42.1...0.42.2","https://github.com/zenml-io/zenml/compare/0.43.0...0.43.1","https://github.com/zenml-io/zenml/compare/0.44.3...0.44.4"]},{"tag_id":"CVE-2026-33032","tag_type":"cve","title":"Nginx UI - Broken Access Control","severity":"critical","actively_exploited":false,"match_field":"url_path","matched_pattern":"/mcp_message","reference_urls":["https://github.com/0xJacky/nginx-ui/security/advisories/GHSA-h6c2-x2m2-mwhf","https://github.com/0xJacky/nginx-ui/commit/413dc631","https://nvd.nist.gov/vuln/detail/CVE-2026-33032"]},{"tag_id":"CVE-2018-20608","tag_type":"cve","title":"Imcat 4.4 - Phpinfo Configuration","severity":"high","actively_exploited":false,"match_field":"url_path","matched_pattern":"/imcat/root/tools/adbug/binfo.php","reference_urls":["https://nvd.nist.gov/vuln/detail/CVE-2018-20608","https://github.com/SexyBeast233/SecBooks"]},{"tag_id":"CVE-2019-11248","tag_type":"cve","title":"Debug Endpoint pprof - Exposure Detection","severity":"high","actively_exploited":false,"match_field":"url_path","matched_pattern":"/debug/pprof","reference_urls":["https://medium.com/bugbountywriteup/my-first-bug-bounty-21d3203ffdb0","http://mmcloughlin.com/posts/your-pprof-is-showing","https://github.com/kubernetes/kubernetes/issues/81023","https://groups.google.com/d/msg/kubernetes-security-announce/pKELclHIov8/BEDtRELACQAJ","https://nvd.nist.gov/vuln/detail/CVE-2019-11248"]},{"tag_id":"CVE-2020-9315","tag_type":"cve","title":"Oracle iPlanet Web Server 7.0.x - Authentication Bypass","severity":"high","actively_exploited":false,"match_field":"url_path","matched_pattern":"/admingui/version/serverConfigurationsGeneral","reference_urls":["https://www.cvebase.com/cve/2020/9315","https://www.oracle.com/support/lifetime-support/","https://www.oracle.com/us/assets/lifetime-support-middleware-069163.pdf","https://wwws.nightwatchcybersecurity.com/2020/05/10/two-vulnerabilities-in-oracles-iplanet-web-server-cve-2020-9315-and-cve-2020-9314/","https://nvd.nist.gov/vuln/detail/CVE-2020-9315"]},{"tag_id":"CVE-2021-37305","tag_type":"cve","title":"Jeecg Boot <= 2.4.5 - Sensitive Information Disclosure","severity":"high","actively_exploited":false,"match_field":"url_path","matched_pattern":"/jeecg-boot/sys/user/querySysUser","reference_urls":["https://github.com/jeecgboot/jeecg-boot/issues/2794","https://nvd.nist.gov/vuln/detail/CVE-2021-37305"]},{"tag_id":"CVE-2022-1392","tag_type":"cve","title":"WordPress Videos sync PDF <=1.7.4 - Local File Inclusion","severity":"high","actively_exploited":false,"match_field":"url_path","matched_pattern":"/wp-content/plugins/video-synchro-pdf/reglages/Menu_Plugins/tout.php","reference_urls":["https://wpscan.com/vulnerability/fe3da8c1-ae21-4b70-b3f5-a7d014aa3815","https://packetstormsecurity.com/files/166534/","https://nvd.nist.gov/vuln/detail/CVE-2022-1392","https://github.com/ARPSyndicate/cvemon","https://github.com/ARPSyndicate/kenzer-templates"]},{"tag_id":"CVE-2022-1711","tag_type":"cve","title":"draw.io < 18.0.5 - Server Side Request Forgery (SSRF)","severity":"high","actively_exploited":false,"match_field":"url_path","matched_pattern":"/proxy?url=http:","reference_urls":["https://huntr.dev/bounties/c32afff5-6ad5-4d4d-beea-f55ab4925797","https://github.com/jgraph/drawio/commit/cf5c78aa0f3127fb10053db55b39f3017a0654ae","https://nvd.nist.gov/vuln/detail/CVE-2022-1711"]},{"tag_id":"CVE-2022-2379","tag_type":"cve","title":"WordPress Easy Student Results <=2.2.8 - Improper Authorization","severity":"high","actively_exploited":false,"match_field":"url_path","matched_pattern":"/wp-json/rps_result/v1/route/search_student","reference_urls":["https://wpscan.com/vulnerability/0773ba24-212e-41d5-9ae0-1416ea2c9db6","https://wordpress.org/plugins/easy-student-results/","https://nvd.nist.gov/vuln/detail/CVE-2022-2379","https://github.com/ARPSyndicate/kenzer-templates","https://github.com/soxoj/information-disclosure-writeups-and-pocs"]},{"tag_id":"CVE-2022-24288","tag_type":"cve","title":"Apache Airflow OS Command Injection","severity":"high","actively_exploited":false,"match_field":"url_path","matched_pattern":"/admin/airflow/code","reference_urls":["https://github.com/advisories/GHSA-3v7g-4pg3-7r6j","https://nvd.nist.gov/vuln/detail/CVE-2022-24288","https://lists.apache.org/thread/dbw5ozcmr0h0lhs0yjph7xdc64oht23t","https://github.com/ARPSyndicate/kenzer-templates","https://github.com/Hax0rG1rl/my_cve_and_bounty_poc"]},{"tag_id":"CVE-2022-2551","tag_type":"cve","title":"WordPress Duplicator <1.4.7 - Authentication Bypass","severity":"high","actively_exploited":false,"match_field":"url_path","matched_pattern":"/wp-content/dup-installer/main.installer.php","reference_urls":["https://wpscan.com/vulnerability/f27d753e-861a-4d8d-9b9a-6c99a8a7ebe0","https://wordpress.org/plugins/duplicator/","https://github.com/SecuriTrust/CVEsLab/tree/main/CVE-2022-2551","https://nvd.nist.gov/vuln/detail/CVE-2022-2551","https://github.com/ARPSyndicate/cvemon"]},{"tag_id":"CVE-2022-34046","tag_type":"cve","title":"WAVLINK WN533A8 - Improper Access Control","severity":"high","actively_exploited":false,"match_field":"url_path","matched_pattern":"/sysinit.shtml","reference_urls":["https://drive.google.com/file/d/18ECQEqZ296LDzZ0wErgqnNfen1jCn0mG/view?usp=sharing","https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-34046","http://packetstormsecurity.com/files/167890/Wavlink-WN533A8-Password-Disclosure.html","https://nvd.nist.gov/vuln/detail/CVE-2022-34046","https://github.com/ARPSyndicate/cvemon"]},{"tag_id":"CVE-2023-4168","tag_type":"cve","title":"Adlisting Classified Ads 2.14.0 - Information Disclosure","severity":"high","actively_exploited":false,"match_field":"url_path","matched_pattern":"/ad-list-search","reference_urls":["https://www.exploit-db.com/exploits/51667","https://templatecookie.com/demo/adlisting-classified-ads-script","https://nvd.nist.gov/vuln/detail/CVE-2023-4168","https://vuldb.com/?ctiid.236184","https://vuldb.com/?id.236184"]},{"tag_id":"CVE-2024-49757","tag_type":"cve","title":"Zitadel - User Registration Bypass","severity":"high","actively_exploited":false,"match_field":"url_path","matched_pattern":"/ui/login/register","reference_urls":["https://github.com/zitadel/zitadel/releases/tag/v2.62.7","https://nvd.nist.gov/vuln/detail/CVE-2024-49757"]},{"tag_id":"CVE-2026-1207","tag_type":"cve","title":"Django RasterField - SQL Injection","severity":"high","actively_exploited":false,"match_field":"url_path","matched_pattern":"/api/raster/search/?band=1)%20AND%201=CAST((SELECT%20version())%20AS%20INT)--","reference_urls":["https://nvd.nist.gov/vuln/detail/CVE-2026-1207","https://www.djangoproject.com/weblog/2026/feb/03/security-releases/","https://github.com/django/django/commit/81aa5292967cd09319c45fe2c1a525ce7b6684d8"]},{"tag_id":"CVE-2026-1557","tag_type":"cve","title":"WP Responsive Images <= 1.0 - Arbitrary File Read","severity":"high","actively_exploited":false,"match_field":"url_path","matched_pattern":"/wp-content/plugins/wp-responsive-images/image_handler.php?src=/wp-config.php","reference_urls":["https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/wp-responsive-images/wp-responsive-images-10-unauthenticated-path-traversal-to-arbitrary-file-read-via-src","https://nvd.nist.gov/vuln/detail/CVE-2026-1557"]},{"tag_id":"CVE-2026-21859","tag_type":"cve","title":"Mailpit < 1.28.3 - Server-Side Request Forgery","severity":"high","actively_exploited":false,"match_field":"url_path","matched_pattern":"/proxy?url=http://127.0.0.1:8025/api/v1/info","reference_urls":["https://rosecurify.com/advisories/RO-26-001-mailpit-server-side-request-forgery-ssrf/","https://github.com/axllent/mailpit/security/advisories/GHSA-8v65-47jx-7mfr"]},{"tag_id":"CVE-2026-23550","tag_type":"cve","title":"Modular DS - Broken Access Control","severity":"high","actively_exploited":false,"match_field":"url_path","matched_pattern":"/api/modular-connector/login","reference_urls":["https://help.modulards.com/en/article/modular-ds-security-release-modular-connector-252-dm3mv0/","https://patchstack.com/database/wordpress/plugin/modular-connector/vulnerability/wordpress-modular-ds-monitor-update-and-backup-multiple-websites-plugin-2-5-1-privilege-escalation-vulnerability"]},{"tag_id":"CVE-2026-25892","tag_type":"cve","title":"Adminer 4.6.2 - 5.4.1 Unauthenticated Persistent DoS","severity":"high","actively_exploited":false,"match_field":"url_path","matched_pattern":"/adminer.php","reference_urls":["https://github.com/vrana/adminer/security/advisories/GHSA-q4f2-39gr-45jh","https://github.com/vrana/adminer/commit/21d3a3150388677b18647d68aec93b7850e457d3"]},{"tag_id":"CVE-2005-2428","tag_type":"cve","title":"Lotus Domino R5 and R6 WebMail - Information Disclosure","severity":"medium","actively_exploited":false,"match_field":"url_path","matched_pattern":"/names.nsf/People","reference_urls":["http://www.cybsec.com/vuln/default_configuration_information_disclosure_lotus_domino.pdf","https://www.exploit-db.com/exploits/39495","https://nvd.nist.gov/vuln/detail/CVE-2005-2428","http://marc.info/?l=bugtraq&m=112240869130356&w=2","http://securitytracker.com/id?1014584"]},{"tag_id":"CVE-2015-8399","tag_type":"cve","title":"Atlassian Confluence <5.8.17 - Information Disclosure","severity":"medium","actively_exploited":false,"match_field":"url_path","matched_pattern":"/spaces/viewdefaultdecorator.action","reference_urls":["https://jira.atlassian.com/browse/CONFSERVER-39704?src=confmacro","https://www.exploit-db.com/exploits/39170/","https://nvd.nist.gov/vuln/detail/CVE-2015-8399"]},{"tag_id":"CVE-2018-10245","tag_type":"cve","title":"AWStats <= 7.5 - Full Path Disclosure","severity":"medium","actively_exploited":false,"match_field":"url_path","matched_pattern":"/awstats/awstats.pl","reference_urls":["https://github.com/eldy/awstats","https://awstats.sourceforge.io/"]},{"tag_id":"CVE-2018-11409","tag_type":"cve","title":"Splunk <=7.0.1 - Information Disclosure","severity":"medium","actively_exploited":false,"match_field":"url_path","matched_pattern":"/__raw/services/server/info/server-info","reference_urls":["https://github.com/kofa2002/splunk","https://www.exploit-db.com/exploits/44865/","http://web.archive.org/web/20211208114213/https://securitytracker.com/id/1041148","https://nvd.nist.gov/vuln/detail/CVE-2018-11409","http://www.securitytracker.com/id/1041148"]},{"tag_id":"CVE-2018-16670","tag_type":"cve","title":"CirCarLife <4.3 - Improper Authentication","severity":"medium","actively_exploited":false,"match_field":"url_path","matched_pattern":"/services/user/values.xml","reference_urls":["https://www.exploit-db.com/exploits/45384","https://github.com/SadFud/Exploits/tree/master/Real%20World/Suites/cir-pwn-life","https://www.exploit-db.com/exploits/45384/","https://nvd.nist.gov/vuln/detail/CVE-2018-16670","https://github.com/20142995/sectool"]},{"tag_id":"CVE-2019-3401","tag_type":"cve","title":"Atlassian Jira <7.13.3/8.0.0-8.1.1 - Incorrect Authorization","severity":"medium","actively_exploited":false,"match_field":"url_path","matched_pattern":"/secure/ManageFilters.jspa?filter=popular&filterView=popular","reference_urls":["https://jira.atlassian.com/browse/JRASERVER-69244","https://nvd.nist.gov/vuln/detail/CVE-2019-3401"]},{"tag_id":"CVE-2019-3403","tag_type":"cve","title":"Jira - Incorrect Authorization","severity":"medium","actively_exploited":false,"match_field":"url_path","matched_pattern":"/rest/api/2/user/picker","reference_urls":["https://jira.atlassian.com/browse/JRASERVER-69242","https://nvd.nist.gov/vuln/detail/CVE-2019-3403","https://github.com/nomi-sec/PoC-in-GitHub","https://github.com/rezasarvani/JiraVulChecker","https://github.com/und3sc0n0c1d0/UserEnumJira"]},{"tag_id":"CVE-2019-8449","tag_type":"cve","title":"Jira <8.4.0 - Information Disclosure","severity":"medium","actively_exploited":false,"match_field":"url_path","matched_pattern":"/rest/api/latest/groupuserpicker","reference_urls":["https://www.doyler.net/security-not-included/more-jira-enumeration","https://jira.atlassian.com/browse/JRASERVER-69796","http://packetstormsecurity.com/files/156172/Jira-8.3.4-Information-Disclosure.html","https://github.com/SexyBeast233/SecBooks","https://github.com/StarCrossPortal/scalpel"]},{"tag_id":"CVE-2020-20285","tag_type":"cve","title":"ZZcms - Cross-Site Scripting","severity":"medium","actively_exploited":false,"match_field":"url_path","matched_pattern":"/user/login.php","reference_urls":["https://github.com/iohex/ZZCMS/blob/master/zzcms2019_login_xss.md","https://nvd.nist.gov/vuln/detail/CVE-2020-20285","https://github.com/ARPSyndicate/kenzer-templates"]},{"tag_id":"CVE-2021-21745","tag_type":"cve","title":"ZTE MF971R - Referer authentication bypass","severity":"medium","actively_exploited":false,"match_field":"url_path","matched_pattern":"/goform/goform_get_cmd_process?cmd=psw_fail_num_str","reference_urls":["https://www.talosintelligence.com/vulnerability_reports/TALOS-2021-1317","https://nvd.nist.gov/vuln/detail/CVE-2021-21745","https://support.zte.com.cn/support/news/LoopholeInfoDetail.aspx?newsId=1019764","https://github.com/ARPSyndicate/kenzer-templates"]},{"tag_id":"CVE-2021-24997","tag_type":"cve","title":"WordPress Guppy <=1.1 - Information Disclosure","severity":"medium","actively_exploited":false,"match_field":"url_path","matched_pattern":"/wp-json/guppy/v2/load-guppy-users","reference_urls":["https://www.exploit-db.com/exploits/50540","https://patchstack.com/database/vulnerability/wp-guppy/wordpress-wp-guppy-plugin-1-2-sensitive-information-disclosure-vulnerability","https://wpscan.com/vulnerability/747e6c7e-a167-4d82-b6e6-9e8613f0e900","https://nvd.nist.gov/vuln/detail/CVE-2021-24997","https://github.com/ARPSyndicate/cvemon"]},{"tag_id":"CVE-2022-24819","tag_type":"cve","title":"XWiki < 12.10.11, 13.4.4 & 13.9-rc-1 - Information Disclosure","severity":"medium","actively_exploited":false,"match_field":"url_path","matched_pattern":"/bin/login/XWikiLogin","reference_urls":["https://github.com/xwiki/xwiki-platform/security/advisories/GHSA-97jg-43c9-q6pf"]},{"tag_id":"CVE-2022-26159","tag_type":"cve","title":"Ametys CMS Information Disclosure","severity":"medium","actively_exploited":false,"match_field":"url_path","matched_pattern":"/plugins/web/service/search/auto-completion/domain/en.xml","reference_urls":["https://nvd.nist.gov/vuln/detail/CVE-2022-26159","https://podalirius.net/en/cves/2022-26159/","https://issues.ametys.org/browse/CMS-10973","https://github.com/p0dalirius/CVE-2022-26159-Ametys-Autocompletion-XML/","https://github.com/ARPSyndicate/cvemon"]},{"tag_id":"CVE-2022-31260","tag_type":"cve","title":"ResourceSpace - Metadata Export","severity":"medium","actively_exploited":false,"match_field":"url_path","matched_pattern":"/pages/csv_export_results_metadata.php","reference_urls":["https://github.com/grymer/CVE/blob/master/CVE-2022-31260.md","https://nvd.nist.gov/vuln/detail/CVE-2022-31260"]},{"tag_id":"CVE-2022-35416","tag_type":"cve","title":"H3C SSL VPN <=2022-07-10 - Cross-Site Scripting","severity":"medium","actively_exploited":false,"match_field":"url_path","matched_pattern":"/wnm/login/login.json","reference_urls":["https://github.com/advisories/GHSA-9x76-78gc-r3m9","https://github.com/Docker-droid/H3C_SSL_VPN_XSS","https://nvd.nist.gov/vuln/detail/CVE-2022-35416","https://github.com/ARPSyndicate/kenzer-templates","https://github.com/bughunter0xff/recon-scanner"]},{"tag_id":"CVE-2023-35155","tag_type":"cve","title":"XWiki - Cross-Site Scripting","severity":"medium","actively_exploited":false,"match_field":"url_path","matched_pattern":"/xwiki/bin/view/Main","reference_urls":["https://jira.xwiki.org/browse/XWIKI-20370","https://nvd.nist.gov/vuln/detail/CVE-2023-35155"]},{"tag_id":"CVE-2023-50720","tag_type":"cve","title":"XWiki < 4.10.15 - Email Disclosure","severity":"medium","actively_exploited":false,"match_field":"url_path","matched_pattern":"/bin/view/Main/Search","reference_urls":["https://jira.xwiki.org/browse/XWIKI-20371","https://nvd.nist.gov/vuln/detail/CVE-2023-50720"]},{"tag_id":"CVE-2024-5230","tag_type":"cve","title":"FleetCart 4.1.1 - Information Disclosure","severity":"medium","actively_exploited":false,"match_field":"url_path","matched_pattern":"/en/products","reference_urls":["https://nvd.nist.gov/vuln/detail/CVE-2024-5230","https://packetstormsecurity.com/files/178770/FleetCart-4.1.1-Information-Disclosure.html","https://codecanyon.net/item/fleetcart-laravel-ecommerce-system/23014826","https://vuldb.com/?ctiid.265981","https://vuldb.com/?id.265981"]},{"tag_id":"CVE-2024-54763","tag_type":"cve","title":"ipTIME A2004 - Unauthorized Access","severity":"medium","actively_exploited":false,"match_field":"url_path","matched_pattern":"/login/hostinfo.cgi","reference_urls":["https://github.com/Shuanunio/CVE_Requests/blob/main/ipTIME/A2004/ipTIME_A2004_unauthorized_access_vulnerability_first.md","https://nvd.nist.gov/vuln/detail/CVE-2024-54763"]},{"tag_id":"CVE-2024-54764","tag_type":"cve","title":"ipTIME A2004 - Unauthorized Access","severity":"medium","actively_exploited":false,"match_field":"url_path","matched_pattern":"/login/hostinfo2.cgi","reference_urls":["https://github.com/Shuanunio/CVE_Requests/blob/main/ipTIME/A2004/ipTIME_A2004_unauthorized_access_vulnerability_second.md","https://nvd.nist.gov/vuln/detail/CVE-2024-54764"]},{"tag_id":"CVE-2024-6188","tag_type":"cve","title":"TrakSYS 11.x.x - Sensitive Data Exposure","severity":"medium","actively_exploited":false,"match_field":"url_path","matched_pattern":"/TS/export/pagedefinition","reference_urls":["https://kiwiyumi.com/post/tracksys-export-source-code/","https://nvd.nist.gov/vuln/detail/CVE-2024-6188","https://www.incibe.es/en/incibe-cert/early-warning/vulnerabilities/cve-2024-6188","https://debricked.com/vulnerability-database/vulnerability/CVE-2024-6188"]},{"tag_id":"CVE-2024-9617","tag_type":"cve","title":"Danswer - Insecure Direct Object Reference","severity":"medium","actively_exploited":false,"match_field":"url_path","matched_pattern":"/api/chat/get-chat-session/1","reference_urls":["https://huntr.com/bounties/8f683ff6-3a99-41c6-b763-a8f7b73bd146","https://github.com/danswer-ai/danswer"]},{"tag_id":"CVE-2026-1277","tag_type":"cve","title":"URL Shortify <= 1.12.1 - Open Redirect","severity":"medium","actively_exploited":false,"match_field":"url_path","matched_pattern":"/wp-admin/admin-ajax.php?action=heartbeat&kc_us_dismiss_admin_notice=1&option_name=bfcm_2025_offer&redirect_to=https://i","reference_urls":["https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/url-shortify/url-shortify-1121-unauthenticated-open-redirect-via-redirect-to-parameter","https://nvd.nist.gov/vuln/detail/CVE-2026-1277"]},{"tag_id":"CVE-2026-24128","tag_type":"cve","title":"XWiki Platform Distribution Flavor Main - Cross-Site Scripting","severity":"medium","actively_exploited":false,"match_field":"url_path","matched_pattern":"/xwiki/bin/view/XWiki/Main?xpage=distribution&extensionSection=progress&extensionId=org.xwiki.platform%3Axwiki-platform-","reference_urls":["https://jira.xwiki.org/browse/XWIKI-23462","https://nvd.nist.gov/vuln/detail/CVE-2026-24128"]},{"tag_id":"CVE-2026-1581","tag_type":"cve","title":"wpForo Forum <= 2.4.14 - SQL Injection","severity":"CRITICAL","actively_exploited":false,"match_field":"url_path","matched_pattern":"/community/recent/?wpfob=(SELECT/**/1/**/FROM/**/(SELECT/**/SLEEP(8))a)","reference_urls":[]},{"tag_id":"CVE-2026-21445","tag_type":"cve","title":"Langflow - Broken Access Control","severity":"CRITICAL","actively_exploited":false,"match_field":"url_path","matched_pattern":"/api/v1/monitor/messages","reference_urls":[]},{"tag_id":"CVE-2026-4020","tag_type":"cve","title":"Gravity SMTP WordPress Plugin - Sensitive Information Exposure","severity":"HIGH","actively_exploited":false,"match_field":"url_path","matched_pattern":"/wp-json/gravitysmtp/v1/tests/mock-data?page=gravitysmtp-settings","reference_urls":[]}],"data_as_of":"2026-10-06T20:37:26.768020+00:00"}