{"ip":"185.141.60.161","total_events":166,"verdict":{"verdict":"scanning","label":"Scanning for known vulnerabilities","detail":"6 exploit-path probe(s)","confidence":"medium","network_type":"CDN","why":["6 request(s) matched a known exploit path.","Only GET/HEAD seen, no request body: scanning for the vulnerability, not delivering a payload.","Not in any known-scanner range."],"engagement":{"level":"payload","label":"Sustained payload","detail":"2,882,167 bytes sent","bytes_sent":2882167,"session_seconds":35,"persistent":false}},"first_seen":"2026-09-24T17:37:01","last_seen":"2026-09-24T18:10:44","events_24h":0,"events_7d":166,"geo":{"country_code":"BG","country_name":"Bulgaria","region":"","city":"","lat":42.696,"lon":23.332,"asn":44901,"org":"Belcloud LTD"},"source_domain":null,"known_scanners":[],"scanner_tag":{"key":"peeringdb:as44901","label":"BelCloud Ltd.","category":"cdn","url":"https://www.peeringdb.com/asn/44901"},"cve_matches":[{"cve_id":"CVE-2022-26143","title":"Mitel MiCollab - Information Disclosure & Denial of Service","severity":"critical","actively_exploited":true,"match_field":"url_path","matched_pattern":"/ucs/micollab/version.json"},{"cve_id":"CVE-2024-1709","title":"ConnectWise ScreenConnect 23.9.7 - Authentication Bypass","severity":"critical","actively_exploited":true,"match_field":"url_path","matched_pattern":"/SetupWizard.aspx"},{"cve_id":"CVE-2025-0282","title":"Ivanti Connect Secure - Stack-based Buffer Overflow","severity":"critical","actively_exploited":true,"match_field":"url_path","matched_pattern":"/dana-na/auth/url_default/welcome.cgi"},{"cve_id":"CVE-2023-38646","title":"Metabase < 0.46.6.1 - Remote Code Execution","severity":"critical","actively_exploited":false,"match_field":"url_path","matched_pattern":"/api/session/properties"},{"cve_id":"CVE-2024-23917","title":"JetBrains TeamCity > 2023.11.3 - Authentication Bypass","severity":"critical","actively_exploited":false,"match_field":"url_path","matched_pattern":"/app/rest/server"},{"cve_id":"CVE-2024-25723","title":"ZenML ZenML Server - Improper Authentication","severity":"critical","actively_exploited":false,"match_field":"url_path","matched_pattern":"/api/v1/info"},{"cve_id":"CVE-2019-11248","title":"Debug Endpoint pprof - Exposure Detection","severity":"high","actively_exploited":false,"match_field":"url_path","matched_pattern":"/debug/pprof"},{"cve_id":"CVE-2024-30569","title":"Netgear R6850 - Information Disclosure","severity":"high","actively_exploited":false,"match_field":"url_path","matched_pattern":"/currentsetting.htm"},{"cve_id":"CVE-2026-25892","title":"Adminer 4.6.2 - 5.4.1 Unauthenticated Persistent DoS","severity":"high","actively_exploited":false,"match_field":"url_path","matched_pattern":"/adminer.php"},{"cve_id":"CVE-2026-35029","title":"LiteLLM - Arbitrary File Read","severity":"high","actively_exploited":false,"match_field":"url_path","matched_pattern":"/health/liveliness"},{"cve_id":"CVE-2007-4556","title":"OpenSymphony XWork/Apache Struts2 - Remote Code Execution","severity":"medium","actively_exploited":false,"match_field":"url_path","matched_pattern":"/login.action"},{"cve_id":"CVE-2025-2129","title":"Mage AI - Insecure Default Authentication Setup","severity":"medium","actively_exploited":false,"match_field":"url_path","matched_pattern":"/api/kernels"}],"malware":[],"top_ports":[{"port":8001,"proto":"tcp","label":"","count":166}],"fingerprints":{"ssh_hassh":[],"tls_ja4":[],"tls_client_hello":"","tls_ja3":[],"http_akin":["a11cun030_0000004c_13ee3d34","a11cun040_0000004d_50f90888","a11cun040_0000004d_2b964f2b","a11cun040_0000004d_aa48e2c8"]},"fingerprint_peers":{"a11cun030_0000004c_13ee3d34":2672,"a11cun040_0000004d_2b964f2b":5,"a11cun040_0000004d_aa48e2c8":3506,"a11cun040_0000004d_50f90888":30},"akin_families":{"a11cun030_0000004c_13ee3d34":{"head":"a11cun030_0000004c_13ee3d34","shapes":2,"ips":2672},"a11cun040_0000004d_50f90888":{"head":"a11cun040_0000004d_aa48e2c8","shapes":4,"ips":3506},"a11cun040_0000004d_aa48e2c8":{"head":"a11cun040_0000004d_aa48e2c8","shapes":4,"ips":3506}},"user_agents":["nerva/1.0","Mozilla/5.0 (iPhone; CPU iPhone OS 13_5_1 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/13.1.1 Mobile/15E148 Safari/604.1","Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/127.0.0.0 Safari/537.36"],"timeline":[{"date":"2026-09-24","count":166}],"recent_events":[{"timestamp":"2026-09-24T18:10:44","port":8001,"proto":"tcp","app_proto":"","app_protocol":"http","host":"<HONEYPOT>","headers":"{\"accept\":\"*/*\",\"accept-encoding\":\"gzip\",\"host\":\"<HONEYPOT>:8001\",\"user-agent\":\"Mozilla/5.0 (iPhone; CPU iPhone OS 13_5_1 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/13.1.1 Mobile/15E148 Safari/604.1\"}","body":"","sni":"","tls_cipher":"","tls_version":"","alpn":[],"url_path":"/","summary":"","payload_hex":"474554202f20485454502f312e310d0a486f73743a20<HONEYPOT>3a383030310d0a557365722d4167656e743a204d6f7a696c6c612f352e3020286950686f6e653b20435055206950686f6e65204f532031335f355f31206c696b65204d6163204f53205829204170706c655765624b69742f3630352e312e313520284b48544d4c2c206c696b65204765636b6f292056657273696f6e2f31332e312e31204d6f62696c652f313545313438205361666172692f3630342e310d0a4163636570743a202a2f2a0d0a4163636570742d456e636f64696e673a20677a69700d0a0d0a","method":"GET","user_agent":"Mozilla/5.0 (iPhone; CPU iPhone OS 13_5_1 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/13.1.1 Mobile/15E148 Safari/604.1","ja3":"","session":"3132e4a5-5b04-426b-8ca1-e92b870a03d8","seq":1,"duration_ms":100,"bytes_in":232,"bytes_out":79},{"timestamp":"2026-09-24T17:37:38","port":8001,"proto":"tcp","app_proto":"","app_protocol":"http","host":"<HONEYPOT>","headers":"{\"accept\":\"application/json\",\"accept-encoding\":\"gzip\",\"host\":\"<HONEYPOT>:8001\",\"user-agent\":\"Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/127.0.0.0 Safari/537.36\"}","body":"","sni":"","tls_cipher":"","tls_version":"","alpn":[],"url_path":"/webpages/login.html","summary":"","payload_hex":"474554202f77656270616765732f6c6f67696e2e68746d6c20485454502f312e310d0a486f73743a20<HONEYPOT>3a383030310d0a557365722d4167656e743a204d6f7a696c6c612f352e30202857696e646f7773204e542031302e303b2057696e36343b2078363429204170706c655765624b69742f3533372e333620284b48544d4c2c206c696b65204765636b6f29204368726f6d652f3132372e302e302e30205361666172692f3533372e33360d0a4163636570743a206170706c69636174696f6e2f6a736f6e0d0a4163636570742d456e636f64696e673a20677a69700d0a0d0a","method":"GET","user_agent":"Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/127.0.0.0 Safari/537.36","ja3":"","session":"f0c6c3c0-aaee-444b-90fe-9a221945062a","seq":157,"duration_ms":34996,"bytes_in":36027,"bytes_out":12403},{"timestamp":"2026-09-24T17:37:38","port":8001,"proto":"tcp","app_proto":"","app_protocol":"http","host":"<HONEYPOT>","headers":"{\"accept\":\"*/*\",\"accept-encoding\":\"gzip\",\"host\":\"<HONEYPOT>:8001\",\"user-agent\":\"Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/127.0.0.0 Safari/537.36\"}","body":"","sni":"","tls_cipher":"","tls_version":"","alpn":[],"url_path":"/ClientWebService/client.asmx","summary":"","payload_hex":"474554202f436c69656e74576562536572766963652f636c69656e742e61736d7820485454502f312e310d0a486f73743a20<HONEYPOT>3a383030310d0a557365722d4167656e743a204d6f7a696c6c612f352e30202857696e646f7773204e542031302e303b2057696e36343b2078363429204170706c655765624b69742f3533372e333620284b48544d4c2c206c696b65204765636b6f29204368726f6d652f3132372e302e302e30205361666172692f3533372e33360d0a4163636570743a202a2f2a0d0a4163636570742d456e636f64696e673a20677a69700d0a0d0a","method":"GET","user_agent":"Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/127.0.0.0 Safari/537.36","ja3":"","session":"f0c6c3c0-aaee-444b-90fe-9a221945062a","seq":158,"duration_ms":35219,"bytes_in":36259,"bytes_out":12482},{"timestamp":"2026-09-24T17:37:37","port":8001,"proto":"tcp","app_proto":"","app_protocol":"http","host":"<HONEYPOT>","headers":"{\"accept\":\"application/json\",\"accept-encoding\":\"gzip\",\"host\":\"<HONEYPOT>:8001\",\"user-agent\":\"Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/127.0.0.0 Safari/537.36\"}","body":"","sni":"","tls_cipher":"","tls_version":"","alpn":[],"url_path":"/hub/login","summary":"","payload_hex":"474554202f6875622f6c6f67696e20485454502f312e310d0a486f73743a20<HONEYPOT>3a383030310d0a557365722d4167656e743a204d6f7a696c6c612f352e30202857696e646f7773204e542031302e303b2057696e36343b2078363429204170706c655765624b69742f3533372e333620284b48544d4c2c206c696b65204765636b6f29204368726f6d652f3132372e302e302e30205361666172692f3533372e33360d0a4163636570743a206170706c69636174696f6e2f6a736f6e0d0a4163636570742d456e636f64696e673a20677a69700d0a0d0a","method":"GET","user_agent":"Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/127.0.0.0 Safari/537.36","ja3":"","session":"f0c6c3c0-aaee-444b-90fe-9a221945062a","seq":153,"duration_ms":34102,"bytes_in":35101,"bytes_out":12087},{"timestamp":"2026-09-24T17:37:37","port":8001,"proto":"tcp","app_proto":"","app_protocol":"http","host":"<HONEYPOT>","headers":"{\"accept\":\"application/json\",\"accept-encoding\":\"gzip\",\"host\":\"<HONEYPOT>:8001\",\"user-agent\":\"Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/127.0.0.0 Safari/537.36\"}","body":"","sni":"","tls_cipher":"","tls_version":"","alpn":[],"url_path":"/api/kernels","summary":"","payload_hex":"474554202f6170692f6b65726e656c7320485454502f312e310d0a486f73743a20<HONEYPOT>3a383030310d0a557365722d4167656e743a204d6f7a696c6c612f352e30202857696e646f7773204e542031302e303b2057696e36343b2078363429204170706c655765624b69742f3533372e333620284b48544d4c2c206c696b65204765636b6f29204368726f6d652f3132372e302e302e30205361666172692f3533372e33360d0a4163636570743a206170706c69636174696f6e2f6a736f6e0d0a4163636570742d456e636f64696e673a20677a69700d0a0d0a","method":"GET","user_agent":"Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/127.0.0.0 Safari/537.36","ja3":"","session":"f0c6c3c0-aaee-444b-90fe-9a221945062a","seq":154,"duration_ms":34325,"bytes_in":35329,"bytes_out":12166},{"timestamp":"2026-09-24T17:37:37","port":8001,"proto":"tcp","app_proto":"","app_protocol":"http","host":"<HONEYPOT>","headers":"{\"accept\":\"application/json\",\"accept-encoding\":\"gzip\",\"host\":\"<HONEYPOT>:8001\",\"user-agent\":\"Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/127.0.0.0 Safari/537.36\"}","body":"","sni":"","tls_cipher":"","tls_version":"","alpn":[],"url_path":"/lab/api/settings","summary":"","payload_hex":"474554202f6c61622f6170692f73657474696e677320485454502f312e310d0a486f73743a20<HONEYPOT>3a383030310d0a557365722d4167656e743a204d6f7a696c6c612f352e30202857696e646f7773204e542031302e303b2057696e36343b2078363429204170706c655765624b69742f3533372e333620284b48544d4c2c206c696b65204765636b6f29204368726f6d652f3132372e302e302e30205361666172692f3533372e33360d0a4163636570743a206170706c69636174696f6e2f6a736f6e0d0a4163636570742d456e636f64696e673a20677a69700d0a0d0a","method":"GET","user_agent":"Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/127.0.0.0 Safari/537.36","ja3":"","session":"f0c6c3c0-aaee-444b-90fe-9a221945062a","seq":155,"duration_ms":34549,"bytes_in":35562,"bytes_out":12245},{"timestamp":"2026-09-24T17:37:37","port":8001,"proto":"tcp","app_proto":"","app_protocol":"http","host":"<HONEYPOT>","headers":"{\"accept\":\"application/json\",\"accept-encoding\":\"gzip\",\"host\":\"<HONEYPOT>:8001\",\"user-agent\":\"Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/127.0.0.0 Safari/537.36\"}","body":"","sni":"","tls_cipher":"","tls_version":"","alpn":[],"url_path":"/openapi.json","summary":"","payload_hex":"474554202f6f70656e6170692e6a736f6e20485454502f312e310d0a486f73743a20<HONEYPOT>3a383030310d0a557365722d4167656e743a204d6f7a696c6c612f352e30202857696e646f7773204e542031302e303b2057696e36343b2078363429204170706c655765624b69742f3533372e333620284b48544d4c2c206c696b65204765636b6f29204368726f6d652f3132372e302e302e30205361666172692f3533372e33360d0a4163636570743a206170706c69636174696f6e2f6a736f6e0d0a4163636570742d456e636f64696e673a20677a69700d0a0d0a","method":"GET","user_agent":"Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/127.0.0.0 Safari/537.36","ja3":"","session":"f0c6c3c0-aaee-444b-90fe-9a221945062a","seq":156,"duration_ms":34773,"bytes_in":35791,"bytes_out":12324},{"timestamp":"2026-09-24T17:37:36","port":8001,"proto":"tcp","app_proto":"","app_protocol":"http","host":"<HONEYPOT>","headers":"{\"accept\":\"text/html\",\"accept-encoding\":\"gzip\",\"host\":\"<HONEYPOT>:8001\",\"user-agent\":\"Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/127.0.0.0 Safari/537.36\"}","body":"","sni":"","tls_cipher":"","tls_version":"","alpn":[],"url_path":"/phpmyadmin/setup/","summary":"","payload_hex":"474554202f7068706d7961646d696e2f73657475702f20485454502f312e310d0a486f73743a20<HONEYPOT>3a383030310d0a557365722d4167656e743a204d6f7a696c6c612f352e30202857696e646f7773204e542031302e303b2057696e36343b2078363429204170706c655765624b69742f3533372e333620284b48544d4c2c206c696b65204765636b6f29204368726f6d652f3132372e302e302e30205361666172692f3533372e33360d0a4163636570743a20746578742f68746d6c0d0a4163636570742d456e636f64696e673a20677a69700d0a0d0a","method":"GET","user_agent":"Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/127.0.0.0 Safari/537.36","ja3":"","session":"f0c6c3c0-aaee-444b-90fe-9a221945062a","seq":149,"duration_ms":33207,"bytes_in":34188,"bytes_out":11771},{"timestamp":"2026-09-24T17:37:36","port":8001,"proto":"tcp","app_proto":"","app_protocol":"http","host":"<HONEYPOT>","headers":"{\"accept\":\"application/json\",\"accept-encoding\":\"gzip\",\"host\":\"<HONEYPOT>:8001\",\"user-agent\":\"Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/127.0.0.0 Safari/537.36\"}","body":"","sni":"","tls_cipher":"","tls_version":"","alpn":[],"url_path":"/Telerik.Web.UI.DialogHandler.aspx","summary":"","payload_hex":"474554202f54656c6572696b2e5765622e55492e4469616c6f6748616e646c65722e6173707820485454502f312e310d0a486f73743a20<HONEYPOT>3a383030310d0a557365722d4167656e743a204d6f7a696c6c612f352e30202857696e646f7773204e542031302e303b2057696e36343b2078363429204170706c655765624b69742f3533372e333620284b48544d4c2c206c696b65204765636b6f29204368726f6d652f3132372e302e302e30205361666172692f3533372e33360d0a4163636570743a206170706c69636174696f6e2f6a736f6e0d0a4163636570742d456e636f64696e673a20677a69700d0a0d0a","method":"GET","user_agent":"Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/127.0.0.0 Safari/537.36","ja3":"","session":"f0c6c3c0-aaee-444b-90fe-9a221945062a","seq":150,"duration_ms":33431,"bytes_in":34438,"bytes_out":11850},{"timestamp":"2026-09-24T17:37:36","port":8001,"proto":"tcp","app_proto":"","app_protocol":"http","host":"<HONEYPOT>","headers":"{\"accept\":\"text/plain\",\"accept-encoding\":\"gzip\",\"host\":\"<HONEYPOT>:8001\",\"user-agent\":\"Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/127.0.0.0 Safari/537.36\"}","body":"","sni":"","tls_cipher":"","tls_version":"","alpn":[],"url_path":"/metrics","summary":"","payload_hex":"474554202f6d65747269637320485454502f312e310d0a486f73743a20<HONEYPOT>3a383030310d0a557365722d4167656e743a204d6f7a696c6c612f352e30202857696e646f7773204e542031302e303b2057696e36343b2078363429204170706c655765624b69742f3533372e333620284b48544d4c2c206c696b65204765636b6f29204368726f6d652f3132372e302e302e30205361666172692f3533372e33360d0a4163636570743a20746578742f706c61696e0d0a4163636570742d456e636f64696e673a20677a69700d0a0d0a","method":"GET","user_agent":"Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/127.0.0.0 Safari/537.36","ja3":"","session":"f0c6c3c0-aaee-444b-90fe-9a221945062a","seq":151,"duration_ms":33655,"bytes_in":34656,"bytes_out":11929}],"http_methods":[{"method":"GET","count":166}],"distinct_ports_total":1,"top_paths":[{"path":"/version","count":4,"ports":1},{"path":"/api/v1/version","count":4,"ports":1},{"path":"/api/version","count":4,"ports":1},{"path":"/login","count":3,"ports":1},{"path":"/+CSCOE+/logon.html","count":2,"ports":1},{"path":"/api/overview","count":2,"ports":1},{"path":"/api/","count":2,"ports":1},{"path":"/","count":2,"ports":1},{"path":"/status","count":2,"ports":1},{"path":"/admin/login","count":1,"ports":1},{"path":"/currentsetting.htm","count":1,"ports":1},{"path":"/v3/api-docs","count":1,"ports":1},{"path":"/WebInterface/","count":1,"ports":1},{"path":"/admin","count":1,"ports":1},{"path":"/adfs/ls","count":1,"ports":1}],"distinct_paths_total":150,"top_snis":[],"top_hosts":[],"top_alpns":[],"banners":[],"credentials":[],"header_profile":{"signature":["Accept","Accept-Encoding","Host","User-Agent"],"representative":[{"name":"Accept","value":"*/*","notable":false},{"name":"Accept-Encoding","value":"gzip","notable":false},{"name":"Host","value":"<HONEYPOT>:8001","notable":false},{"name":"User-Agent","value":"Mozilla/5.0 (iPhone; CPU iPhone OS 13_5_1 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/13.1.1 Mobile/15E148 Safari/604.1","notable":false}],"distinct_sets":1,"events_with_headers":10},"tags":[{"tag_id":"CVE-2022-26143","tag_type":"cve","title":"Mitel MiCollab - Information Disclosure & Denial of Service","severity":"critical","actively_exploited":true,"match_field":"url_path","matched_pattern":"/ucs/micollab/version.json","reference_urls":["https://nvd.nist.gov/vuln/detail/CVE-2022-26143"]},{"tag_id":"CVE-2024-1709","tag_type":"cve","title":"ConnectWise ScreenConnect 23.9.7 - Authentication Bypass","severity":"critical","actively_exploited":true,"match_field":"url_path","matched_pattern":"/SetupWizard.aspx","reference_urls":["https://www.huntress.com/blog/a-catastrophe-for-control-understanding-the-screenconnect-authentication-bypass","https://github.com/watchtowrlabs/connectwise-screenconnect_auth-bypass-add-user-poc","https://www.connectwise.com/company/trust/security-bulletins/connectwise-screenconnect-23.9.8","https://nvd.nist.gov/vuln/detail/CVE-2024-1709","https://github.com/rapid7/metasploit-framework/pull/18870"]},{"tag_id":"CVE-2025-0282","tag_type":"cve","title":"Ivanti Connect Secure - Stack-based Buffer Overflow","severity":"critical","actively_exploited":true,"match_field":"url_path","matched_pattern":"/dana-na/auth/url_default/welcome.cgi","reference_urls":["https://forums.ivanti.com/s/article/Security-Advisory-Ivanti-Connect-Secure-Policy-Secure-ZTA-Gateways-CVE-2025-0282-CVE-2025-0283","https://labs.watchtowr.com/exploitation-walkthrough-and-techniques-ivanti-connect-secure-rce-cve-2025-0282/","https://cloud.google.com/blog/topics/threat-intelligence/ivanti-connect-secure-vpn-zero-day","https://nvd.nist.gov/vuln/detail/CVE-2025-0282"]},{"tag_id":"CVE-2023-38646","tag_type":"cve","title":"Metabase < 0.46.6.1 - Remote Code Execution","severity":"critical","actively_exploited":false,"match_field":"url_path","matched_pattern":"/api/session/properties","reference_urls":["https://www.metabase.com/blog/security-advisory","https://github.com/metabase/metabase/releases/tag/v0.46.6.1","https://mp.weixin.qq.com/s/ATFwFl-D8k9QfQfzKjZFDg","https://news.ycombinator.com/item?id=36812256","https://blog.assetnote.io/2023/07/22/pre-auth-rce-metabase/"]},{"tag_id":"CVE-2024-23917","tag_type":"cve","title":"JetBrains TeamCity > 2023.11.3 - Authentication Bypass","severity":"critical","actively_exploited":false,"match_field":"url_path","matched_pattern":"/app/rest/server","reference_urls":["https://github.com/fkie-cad/nvd-json-data-feeds","https://www.rapid7.com/db/vulnerabilities/jetbrains-teamcity-cve-2024-23917/"]},{"tag_id":"CVE-2024-25723","tag_type":"cve","title":"ZenML ZenML Server - Improper Authentication","severity":"critical","actively_exploited":false,"match_field":"url_path","matched_pattern":"/api/v1/info","reference_urls":["https://www.zenml.io/blog/critical-security-update-for-zenml-users","https://github.com/zenml-io/zenml","https://github.com/zenml-io/zenml/compare/0.42.1...0.42.2","https://github.com/zenml-io/zenml/compare/0.43.0...0.43.1","https://github.com/zenml-io/zenml/compare/0.44.3...0.44.4"]},{"tag_id":"CVE-2019-11248","tag_type":"cve","title":"Debug Endpoint pprof - Exposure Detection","severity":"high","actively_exploited":false,"match_field":"url_path","matched_pattern":"/debug/pprof","reference_urls":["https://medium.com/bugbountywriteup/my-first-bug-bounty-21d3203ffdb0","http://mmcloughlin.com/posts/your-pprof-is-showing","https://github.com/kubernetes/kubernetes/issues/81023","https://groups.google.com/d/msg/kubernetes-security-announce/pKELclHIov8/BEDtRELACQAJ","https://nvd.nist.gov/vuln/detail/CVE-2019-11248"]},{"tag_id":"CVE-2024-30569","tag_type":"cve","title":"Netgear R6850 - Information Disclosure","severity":"high","actively_exploited":false,"match_field":"url_path","matched_pattern":"/currentsetting.htm","reference_urls":["https://github.com/funny-mud-peee/IoT-vuls/blob/main/netgear%20R6850/Info%20Leak%20in%20Netgear-R6850%EF%BC%88currentsetting.htm%EF%BC%89.md","https://nvd.nist.gov/vuln/detail/CVE-2024-30569","https://www.netgear.com/about/security/"]},{"tag_id":"CVE-2026-25892","tag_type":"cve","title":"Adminer 4.6.2 - 5.4.1 Unauthenticated Persistent DoS","severity":"high","actively_exploited":false,"match_field":"url_path","matched_pattern":"/adminer.php","reference_urls":["https://github.com/vrana/adminer/security/advisories/GHSA-q4f2-39gr-45jh","https://github.com/vrana/adminer/commit/21d3a3150388677b18647d68aec93b7850e457d3"]},{"tag_id":"CVE-2026-35029","tag_type":"cve","title":"LiteLLM - Arbitrary File Read","severity":"high","actively_exploited":false,"match_field":"url_path","matched_pattern":"/health/liveliness","reference_urls":["https://github.com/BerriAI/litellm","https://sec-consult.com/vulnerability-lab/advisory/broken-access-control-in-config-endpoint-in-litellm/","https://nvd.nist.gov/vuln/detail/CVE-2026-35029"]},{"tag_id":"CVE-2007-4556","tag_type":"cve","title":"OpenSymphony XWork/Apache Struts2 - Remote Code Execution","severity":"medium","actively_exploited":false,"match_field":"url_path","matched_pattern":"/login.action","reference_urls":["https://www.guildhab.top/?p=2326","https://nvd.nist.gov/vuln/detail/CVE-2007-4556","https://cwiki.apache.org/confluence/display/WW/S2-001","http://forums.opensymphony.com/ann.jspa?annID=54","http://issues.apache.org/struts/browse/WW-2030"]},{"tag_id":"CVE-2025-2129","tag_type":"cve","title":"Mage AI - Insecure Default Authentication Setup","severity":"medium","actively_exploited":false,"match_field":"url_path","matched_pattern":"/api/kernels","reference_urls":["https://nvd.nist.gov/vuln/detail/CVE-2025-2129","https://github.com/zn9988/publications/blob/main/2.Mage-AI%20-%20Insecure%20Default%20Authentication%20Setup%20Leading%20to%20Zero-Click%20RCE/README.md","https://vuldb.com/?ctiid.299049","https://vuldb.com/?id.299049","https://vuldb.com/?submit.510690"]}],"data_as_of":"2026-09-30T01:06:31.046040+00:00"}