>> All posts>> Topic

Threats

352 articles.

July 15, 2026ThreatsAttack surface

CVE-2026-15410: SonicWall SMA1000 command injection, actively exploited

A post-authentication command-injection flaw in SonicWall's SMA1000 access appliances is being exploited in the wild, chained with a companion bug. Here's what you need to know — and how BreachRisk surfaces exposed appliances.

June 15, 2026ThreatsAttack surface

CVE-2026-35273: Oracle PeopleSoft PeopleTools unauthenticated RCE, exploited as a zero-day

A missing-authentication flaw in PeopleSoft PeopleTools' Environment Management component lets an unauthenticated attacker take over the server — exploited as a zero-day by an extortion group against 100+ organizations. It's in CISA's KEV catalog. Here's the risk, and how BreachRisk finds and safely confirms exposed PeopleSoft.

June 10, 2026ThreatsAttack surface

CVE-2026-44277: Fortinet FortiAuthenticator improper access control, patched before exploitation

An improper-access-control flaw in Fortinet FortiAuthenticator could let an unauthenticated attacker reach protected API functionality. It was found internally and patched, with no known exploitation yet. Here's a level-headed read, and how BreachRisk finds exposed FortiAuthenticator.

June 10, 2026ThreatsAttack surface

CVE-2026-34909: Ubiquiti UniFi OS path traversal, actively exploited

A path-traversal flaw in UniFi OS devices lets an unauthenticated attacker reach internal handlers and read files that lead to account access. It's in CISA's KEV catalog with active exploitation. Here's what to do, and how BreachRisk finds exposed devices.

June 10, 2026ThreatsAttack surface

CVE-2026-22557: Ubiquiti UniFi Network Application path traversal

A path-traversal flaw in the UniFi Network Application lets an actor with network access read files off the system, which can be leveraged toward account access. A fix exists; here's the honest severity, and how BreachRisk finds exposed controllers.

June 10, 2026ThreatsAttack surface

CVE-2024-21182: Oracle WebLogic unauthenticated data exposure via T3/IIOP, exploited

A flaw in Oracle WebLogic's core lets an unauthenticated attacker reach critical data over the T3 and IIOP protocols — now in CISA's KEV catalog on evidence of active exploitation. Here's the risk, and how BreachRisk finds exposed WebLogic.

June 9, 2026ThreatsAttack surface

CVE-2026-28318: SolarWinds Serv-U unauthenticated denial-of-service, KEV-listed

A crafted request can crash SolarWinds Serv-U without authentication, taking file transfer offline. It's in CISA's KEV catalog. The impact is availability, not data loss — here's the honest read, and how BreachRisk flags exposed servers.

June 9, 2026ThreatsAttack surface

CVE-2025-53020: Apache HTTP Server memory-leak denial of service

A memory-management flaw in Apache HTTP Server can be pushed toward denial of service — availability only, not code execution, and not known to be exploited. Here's the honest read, and how BreachRisk finds affected servers.

June 3, 2026ThreatsApplication security

CVE-2026-45659: Microsoft SharePoint Server authenticated deserialization RCE, in CISA KEV

A deserialization flaw in on-premises SharePoint Server lets an authenticated attacker run code over the network. It's an 8.8 and it's in CISA's KEV catalog. Here's what to do, and how BreachRisk finds exposed SharePoint.

June 3, 2026ThreatsApplication security

CVE-2026-26980: Ghost CMS unauthenticated SQL injection reads the database

A SQL injection flaw in Ghost CMS lets an unauthenticated attacker read arbitrary data straight from the database. A fix is out in 6.19.1. Here's the risk, and how BreachRisk finds exposed Ghost sites.

June 3, 2026ThreatsApplication security

CVE-2026-26194: Gogs release-deletion argument injection

An argument-injection flaw in Gogs' release-deletion handling lets a low-privileged user smuggle Git options via a crafted tag name. A fix is out in 0.14.2. Here's the risk, and how BreachRisk finds exposed Gogs instances.

June 3, 2026ThreatsApplication security

CVE-2026-22679: Weaver (Fanwei) E-cology unauthenticated RCE via exposed debug endpoint, exploited in the wild

A missing-authentication flaw in Weaver E-cology exposes a debug endpoint that lets an unauthenticated attacker run OS commands — a 9.8 with confirmed in-the-wild exploitation. Here's what to do, and how BreachRisk finds exposed servers.

June 3, 2026ThreatsAttack surface

CVE-2025-8110: Gogs symlink path traversal leads to code execution, in CISA KEV

Improper symbolic-link handling in Gogs' PutContents API lets an authenticated user traverse outside the repo and reach code execution. It's in CISA KEV. Here's what to do, and how BreachRisk finds exposed instances.

June 3, 2026ThreatsApplication security

CVE-2024-39932: Gogs argument-injection flaws in change preview and release tagging

Two argument-injection flaws in Gogs let an authenticated user smuggle Git options into server-side commands — one during change previews, one during release tagging. Here's the risk, and how BreachRisk finds exposed Gogs instances.

June 3, 2026ThreatsApplication security

CVE-2024-39930: Gogs built-in SSH server argument injection leads to RCE

An argument-injection flaw in the built-in SSH server of Gogs lets an authenticated user run commands on the host. A fix is available. Here's the risk, and how BreachRisk finds exposed Gogs instances.

June 3, 2026ThreatsAttack surface

CVE-2023-38646: Metabase pre-authentication remote code execution

A flaw in Metabase lets an unauthenticated attacker run arbitrary commands on the server at its privilege level. It was widely exploited after a public proof-of-concept. Here's what to do, and how BreachRisk finds exposed Metabase.

June 2, 2026ThreatsApplication security

CVE-2024-42009: Roundcube Webmail cross-site scripting that can steal and send a victim's email

A cross-site scripting flaw in Roundcube's message rendering lets a crafted email read, exfiltrate, and send mail as the victim. It's in CISA's KEV catalog and scored 9.3. Here's the risk, and how BreachRisk finds exposed Roundcube instances.

June 2, 2026ThreatsApplication security

CVE-2023-43770: Roundcube Webmail cross-site scripting, used for credential theft

A cross-site scripting flaw in how Roundcube renders links in plaintext email lets an attacker run script in a victim's session. It's in CISA's KEV catalog. Here's the risk, and how BreachRisk finds exposed Roundcube instances.

June 2, 2026ThreatsApplication security

CVE-2021-44026: Roundcube Webmail SQL injection, exploited by state-linked actors

A SQL injection in Roundcube's search handling lets an authenticated user reach the mail database. It's in CISA's KEV catalog and tied to espionage against webmail servers. Here's the risk, and how BreachRisk finds exposed Roundcube instances.

June 1, 2026ThreatsAttack surface

CVE-2026-0257: Palo Alto PAN-OS GlobalProtect authentication bypass, actively exploited

An authentication-bypass flaw in the PAN-OS GlobalProtect portal and gateway lets an attacker establish an unauthorized VPN connection. It's in CISA KEV with limited in-the-wild exploitation. Here's what to do, and how BreachRisk finds exposed portals.

May 11, 2026ThreatsAttack surface

CVE-2026-0300: Palo Alto PAN-OS User-ID Authentication Portal unauthenticated RCE, root-level

A buffer overflow in the PAN-OS User-ID Authentication Portal lets an unauthenticated attacker run code as root by sending crafted packets. It's in CISA KEV with in-the-wild exploitation. Here's what to do, and how BreachRisk finds exposed portals.

May 1, 2026ThreatsAttack surface

CVE-2026-34197: Apache ActiveMQ code execution via the Jolokia API

A code-injection flaw in Apache ActiveMQ's Jolokia JMX-HTTP bridge lets an attacker load a remote Spring context and run code on the broker's JVM. It's in CISA KEV. Authentication is usually required — but default and missing credentials often remove that barrier. Here's what to do, and how BreachRisk finds exposed brokers.

May 1, 2026ThreatsAttack surface

CVE-2026-20133: Cisco Catalyst SD-WAN Manager information disclosure, exploited in the wild

An access-restriction flaw in Cisco Catalyst SD-WAN Manager lets an unauthenticated attacker read sensitive files via the API. It's in CISA's KEV catalog and has been exploited in the wild, chained with two related bugs. Here's what to do, and how BreachRisk finds exposed SD-WAN Manager.

May 1, 2026ThreatsApplication security

CVE-2025-48700: Zimbra Collaboration Classic UI XSS, exploited in the wild

A cross-site scripting flaw in Zimbra's Classic Web Client runs attacker JavaScript when a victim simply views a crafted email — no clicking required. It's in CISA's KEV catalog. Here's the risk, and how BreachRisk finds exposed Zimbra.

May 1, 2026ThreatsApplication security

CVE-2025-2749: Kentico Xperience path traversal and file upload leading to RCE

A flaw in Kentico Xperience's Staging Sync Server lets an attacker write files to path-relative locations and reach remote code execution. It's in CISA's KEV catalog. Here's what to do, and how BreachRisk finds exposed Kentico.

May 1, 2026ThreatsAttack surface

CVE-2024-7399: Samsung MagicINFO 9 Server path traversal, actively exploited

A path-traversal flaw in Samsung MagicINFO 9 Server lets an unauthenticated attacker write files with system authority — a direct route to remote code execution. It's in CISA's KEV catalog. Here's what to do, and how BreachRisk finds exposed servers.

May 1, 2026ThreatsAttack surface

CVE-2024-3721: TBK DVR OS command injection, swept up by botnets

A command-injection flaw in TBK DVR video recorders lets attackers run OS commands on the device. A public exploit exists and these internet-facing recorders are routine botnet fodder. Here's the risk, and how BreachRisk finds exposed units.

April 28, 2026ThreatsAttack surface

Exposed VMware ESXi logins and password spraying

A VMware ESXi login on the public internet is a standing target for password spraying, and weak or reused credentials turn that exposure into control of your hypervisor — a favorite ransomware target. Here's the risk, and how BreachRisk safely tests whether those logins hold.

April 28, 2026ThreatsAttack surface

Exposed phpMyAdmin logins and password spraying

A phpMyAdmin login on the public internet is a standing target for password spraying, and one weak or reused credential can hand an attacker direct access to your database. Here's the risk, and how BreachRisk safely tests whether those logins hold.

April 28, 2026ThreatsAttack surface

Exposed Nextcloud logins and password spraying

A Nextcloud login on the public internet is a standing target for password spraying, and one weak or reused credential can hand an attacker the files and collaboration data it holds. Here's the risk, and how BreachRisk safely tests whether those logins hold.

April 28, 2026ThreatsAttack surface

Exposed MOVEit Transfer logins and password spraying

A MOVEit Transfer login on the public internet is a standing target for password spraying, and one weak or reused credential can hand an attacker a managed-file-transfer system known to hold sensitive data. Here's the risk, and how BreachRisk safely tests whether those logins hold.

April 28, 2026ThreatsAttack surface

Exposed Cisco router logins and password spraying

A Cisco router login on the public internet is a standing target for password spraying, and one weak or reused credential turns that exposure into control of a device that steers your traffic. Here's the risk — and how BreachRisk safely tests whether those logins hold.

April 13, 2026ThreatsAttack surface

CVE-2025-10035: Fortra GoAnywhere MFT deserialization to command injection, actively exploited

A deserialization flaw in GoAnywhere MFT's License Servlet lets an attacker with a forged license signature run commands on the server. It's a 10.0, it's in CISA KEV, and it was exploited as a zero-day by a ransomware group. Here's what to do, and how BreachRisk finds exposed GoAnywhere.

April 13, 2026ThreatsAttack surface

CVE-2024-57726 (with CVE-2024-57728): SimpleHelp privilege escalation to remote code execution

A missing-authorization flaw in SimpleHelp lets a low-privilege user escalate to admin, and a companion file-upload bug turns admin access into code execution. Both are in CISA KEV and tied to real intrusions. Here's what to do, and how BreachRisk finds exposed SimpleHelp servers.

April 13, 2026ThreatsAttack surface

CVE-2024-27198: JetBrains TeamCity authentication bypass, mass-exploited

A pair of flaws in on-premises JetBrains TeamCity let an unauthenticated attacker bypass authentication and take administrative control of the build server. Both are in CISA's KEV catalog and were exploited at scale. Here's what to do, and how BreachRisk finds exposed TeamCity.

April 7, 2026ThreatsAttack surface

CVE-2026-35616: Fortinet FortiClient EMS improper access control, exploited as a zero-day

An access-control flaw in Fortinet FortiClient EMS lets an unauthenticated attacker bypass API authorization and run commands on the management server. It was exploited as a zero-day and is in CISA KEV with a three-day deadline. Here's what to do, and how BreachRisk finds exposed EMS.

April 6, 2026ThreatsAttack surface

CVE-2026-2699: ShareFile Storage Zones Controller improper access control

An access-control flaw in customer-managed ShareFile Storage Zones Controller lets an unauthenticated attacker reach restricted configuration pages — a path to changing system settings and potentially remote code execution. A proof-of-concept is public. Here's what to do, and how BreachRisk finds exposed SZC instances.

April 6, 2026ThreatsAttack surface

CVE-2025-32975: Quest KACE SMA authentication bypass, now in CISA KEV

An authentication-bypass flaw in Quest KACE Systems Management Appliance lets an attacker impersonate legitimate users through the SSO handler — up to full administrative takeover. It's a 10.0 and now KEV-listed. Here's what to do, and how BreachRisk finds exposed KACE appliances.

April 3, 2026ThreatsAttack surface

CVE-2026-3564: ConnectWise ScreenConnect privilege escalation via server cryptographic material

A ScreenConnect flaw could let an attacker who already holds the server's authentication cryptographic material gain elevated access. It carries a high vendor CVSS but has no known exploitation and is not in KEV. Here's a measured read, and how BreachRisk finds exposed ScreenConnect servers.

April 3, 2026ThreatsAttack surface

CVE-2026-27685: SAP NetWeaver Enterprise Portal deserialization of untrusted data

A deserialization flaw in SAP NetWeaver Enterprise Portal Administration lets a privileged user upload content that, when deserialized, can fully compromise the host. It's serious on impact but requires privileged access and isn't known-exploited yet. Here's what to do, and how BreachRisk finds exposed NetWeaver portals.

April 3, 2026ThreatsApplication security

CVE-2026-20963: Microsoft SharePoint unauthenticated deserialization RCE, actively exploited

A deserialization flaw in on-premises SharePoint lets an unauthenticated attacker run code over the network — a 9.8, in CISA's KEV catalog with a same-week deadline. Here's what to do, and how BreachRisk finds exposed SharePoint.

April 3, 2026ThreatsAttack surface

CVE-2025-3935: ConnectWise ScreenConnect ViewState code injection, exploited in targeted intrusions

A ViewState deserialization flaw in ScreenConnect can lead to code execution — but only for an attacker who already holds the server's machine keys. It's in CISA's KEV catalog. Here's the real risk, and how BreachRisk finds exposed ScreenConnect servers.

March 26, 2026ThreatsAttack surface

CVE-2026-3055: Citrix NetScaler SAML IdP memory over-read, actively exploited

Another NetScaler memory over-read — this one reachable when the appliance is configured as a SAML Identity Provider, a common single-sign-on setup. It's unauthenticated, in CISA's KEV catalog, and being exploited. Here's what to do, and how BreachRisk finds exposed appliances.

March 26, 2026ThreatsAttack surface

CVE-2026-21992: Oracle Identity Manager unauthenticated RCE (out-of-band fix)

A missing-authentication flaw in Oracle Identity Manager and Web Services Manager lets an unauthenticated attacker take over the server — serious enough that Oracle shipped a rare out-of-band Security Alert. Here's the risk, and how BreachRisk finds exposed instances.

March 12, 2026ThreatsAttack surface

CVE-2017-7921: Hikvision camera authentication bypass, actively exploited

An authentication bypass in a range of Hikvision IP cameras lets an unauthenticated attacker escalate privileges and pull sensitive data, including credentials. It's in CISA KEV. Here's what to do, and how BreachRisk finds exposed cameras.

March 11, 2026ThreatsApplication security

CVE-2026-22720: VMware Aria Operations stored cross-site scripting, patch available

A stored cross-site scripting flaw in VMware Aria Operations lets a privileged user inject script that runs administrative actions in another user's session. It needs an authenticated foothold, a fix is out, and it isn't being exploited. Here's the honest read, and how BreachRisk finds exposed Aria panels.

March 2, 2026ThreatsAttack surface

CVE-2025-40536: SolarWinds Help Desk Security Control Bypass Vulnerability Exploitation (CVE-2025-40536)

SolarWinds Web Help Desk was found to be susceptible to a security control bypass vulnerability that if exploited, could allow an unauthenticated attacker to gain access to certain restricted functionality.

March 2, 2026ThreatsAttack surface

CVE-2025-40538: SolarWinds Serv-U privilege escalation requiring admin access

A broken-access-control flaw in SolarWinds Serv-U lets an existing admin create a system administrator and run code — but it needs admin privileges to begin with. Here's the honest read, and how BreachRisk flags exposed instances.

March 2, 2026ThreatsAttack surface

CVE-2025-40536: SolarWinds Web Help Desk security-control bypass, actively exploited

A security-control bypass in SolarWinds Web Help Desk lets an unauthenticated attacker reach restricted functionality. It's in CISA's KEV catalog with a very short remediation window. Here's what to do, and how BreachRisk finds exposed Web Help Desk instances.

February 25, 2026ThreatsAttack surface

CVE-2025-68645: Zimbra Collaboration file inclusion, actively exploited

A file-inclusion flaw in Zimbra Collaboration's Webmail Classic UI lets a remote attacker influence internal request dispatching and include arbitrary files from the web root. It's in CISA's KEV catalog. Here's what to do, and how BreachRisk finds exposed servers.

February 25, 2026ThreatsAttack surface

CVE-2024-37079: VMware vCenter Server heap-overflow RCE, in CISA KEV

Another heap-overflow in vCenter Server's DCERPC implementation lets a network attacker run code on your virtualization control plane. It's a 9.8 and it's in CISA's KEV catalog. Here's what to do, and how BreachRisk finds exposed vCenter.

February 24, 2026ThreatsApplication security

CVE-2025-68461: Roundcube Webmail cross-site scripting via SVG animate tag, in KEV

A cross-site scripting flaw via the SVG animate tag lets a crafted email run script in a Roundcube user's session. It's in CISA's KEV catalog. Here's the risk, and how BreachRisk finds exposed Roundcube instances.

February 24, 2026ThreatsApplication security

CVE-2025-49113: Roundcube Webmail post-authentication remote code execution, actively exploited

A PHP object-deserialization flaw lets an authenticated Roundcube user run code on the mail server. It's in CISA's KEV catalog and exploitation went wide within days of disclosure. Here's what to do, and how BreachRisk finds exposed Roundcube instances.

February 24, 2026ThreatsAttack surface

CVE-2025-40551: SolarWinds Web Help Desk unauthenticated deserialization RCE

An untrusted-data deserialization flaw in SolarWinds Web Help Desk allows unauthenticated remote code execution. It's in CISA's KEV catalog with a very short remediation window. Here's what to do, and how BreachRisk finds exposed Web Help Desk instances.

February 24, 2026ThreatsAttack surface

CVE-2025-26399: SolarWinds Web Help Desk unauthenticated deserialization RCE (patch-bypass)

An unauthenticated AjaxProxy deserialization flaw in SolarWinds Web Help Desk allows remote code execution — and it's the third turn of a patch-bypass chain. It's in CISA's KEV catalog. Here's what to do, and how BreachRisk finds exposed Web Help Desk instances.

February 24, 2026ThreatsApplication security

CVE-2023-5631: Roundcube Webmail stored cross-site scripting, exploited as a zero-day by an APT

A stored cross-site scripting flaw via a crafted SVG in HTML email let attackers run script in a Roundcube session. It was exploited as a zero-day for espionage and is in CISA's KEV catalog. Here's the risk, and how BreachRisk finds exposed Roundcube instances.

February 23, 2026ThreatsAttack surface

Exposed UniFi Network logins and password spraying

A UniFi Network controller login on the public internet is a standing target for password spraying, and one weak or reused credential turns that exposure into control of your network infrastructure. Here's the risk — and how BreachRisk safely tests whether those logins hold.

February 23, 2026ThreatsApplication security

Exposed SonarQube logins and password spraying

A SonarQube login on the public internet is a standing target for password spraying, and one weak or reused credential turns that exposure into access to source code and CI secrets. Here's the risk — and how BreachRisk safely tests whether those logins hold.

February 23, 2026ThreatsAttack surface

Exposed SolarWinds Help Desk logins and password spraying

A SolarWinds Help Desk login on the public internet is a standing target for password spraying, and one weak or reused credential turns that exposure into access to tickets and administrative controls. Here's the risk — and how BreachRisk safely tests whether those logins hold.

February 23, 2026ThreatsAttack surface

Exposed SAP Fiori logins and password spraying

An SAP Fiori launchpad login on the public internet is a standing target for password spraying, and one weak or reused credential turns that exposure into access to business-critical ERP data. Here's the risk — and how BreachRisk safely tests whether those logins hold.

February 23, 2026ThreatsAttack surface

Exposed Proofpoint email security logins and password spraying

A Proofpoint email security login on the public internet is a standing target for password spraying, and one weak or reused credential turns that exposure into access to email flow and controls. Here's the risk — and how BreachRisk safely tests whether those logins hold.

February 23, 2026ThreatsApplication security

Exposed JFrog logins and password spraying

A JFrog login on the public internet is a standing target for password spraying, and one weak or reused credential can hand an attacker your artifacts, packages, and build outputs. Here's the risk, and how BreachRisk safely tests whether those logins hold.

February 23, 2026ThreatsAttack surface

Exposed Cisco ISE logins and password spraying

A Cisco Identity Services Engine login on the public internet is a standing target for password spraying, and one weak or reused credential can hand over the system that decides who gets on your network. Here's the risk — and how BreachRisk safely tests whether those logins hold.

February 23, 2026ThreatsAttack surface

Exposed 3CX Webclient logins and password spraying

A 3CX Webclient login on the public internet is a standing target for password spraying, and weak or reused credentials turn that exposure into access to your phone system and its data. Here's the risk, and how BreachRisk safely tests whether that login holds.

February 13, 2026ThreatsAttack surface

CVE-2026-1603: Ivanti Endpoint Manager authentication bypass, unauthenticated credential-data leak

An authentication bypass in Ivanti Endpoint Manager lets a remote, unauthenticated attacker leak specific stored credential data. It's in CISA's KEV catalog. Here's the honest read, and how BreachRisk finds exposed servers.

February 10, 2026ThreatsApplication security

Exposed Jenkins logins and password spraying

A Jenkins login on the public internet is a standing target for password spraying, and one weak or reused credential turns your build server — and the secrets and source it holds — into an attacker's foothold. Here's the risk, and how BreachRisk safely tests whether those logins hold.

January 30, 2026ThreatsAttack surface

CVE-2026-1281: Ivanti Endpoint Manager Mobile code injection, unauthenticated RCE

A code-injection flaw in Ivanti Endpoint Manager Mobile lets a remote, unauthenticated attacker run code on the server that manages your mobile fleet. It's in CISA's KEV catalog. Here's what to do, and how BreachRisk finds exposed servers.

January 26, 2026ThreatsAttack surface

Exposed Progress WhatsUp Gold logins and password spraying

Progress WhatsUp Gold is a network monitoring platform, so an exposed login is a high-value target with broad visibility into — and stored credentials for — your infrastructure. Here's the risk, and how BreachRisk safely tests whether that login holds.

January 26, 2026ThreatsAttack surface

Exposed Kaseya VSA logins and password spraying

Kaseya VSA is a remote monitoring and management platform, so an exposed login is a high-value target with reach across every managed endpoint. Here's the risk, and how BreachRisk safely tests whether that login holds.

January 14, 2026ThreatsAttack surface

Exposed Webmin logins and password spraying

Webmin is a browser-based server administration panel, and an exposed one is a high-value login to spray. Weak or reused credentials turn that exposure into hands-on server control. Here's the risk, and how BreachRisk safely tests whether the login holds.

January 14, 2026ThreatsCloud

Exposed VMware Cloud Orchestrator logins and password spraying

A VMware Cloud Orchestrator login on the public internet is a standing target for password spraying, and one weak or reused credential turns that exposure into access to automation that reaches across your virtual infrastructure. Here's the risk — and how BreachRisk safely tests whether those logins hold.

January 14, 2026ThreatsAttack surface

Exposed Verint Experience Management logins and password spraying

A Verint Experience Management login on the public internet is a standing target for password spraying, and one weak or reused credential turns that exposure into access to customer-experience data. Here's the risk — and how BreachRisk safely tests whether those logins hold.

January 14, 2026ThreatsAttack surface

Exposed TP-Link router logins and password spraying

A TP-Link router admin login on the public internet is a standing target for password spraying, and one weak or default credential turns that exposure into control of your network edge. Here's the risk — and how BreachRisk safely tests whether those logins hold.

January 14, 2026ThreatsAttack surface

Exposed Tableau logins and password spraying

A Tableau login on the public internet is a standing target for password spraying, and one weak or reused credential turns that exposure into access to dashboards and the data behind them. Here's the risk — and how BreachRisk safely tests whether those logins hold.

January 14, 2026ThreatsAttack surface

SonicWall Network Security Appliance Password Spraying

Attempt authentication to SonicWall Network Security Appliance using exposed or weak credentials.

January 14, 2026ThreatsAttack surface

Exposed SonicWall Network Security Appliance logins and password spraying

A SonicWall Network Security Appliance management login on the public internet is a standing target for password spraying, and weak or reused credentials turn that exposure into control of the firewall itself. Here's the risk, and how BreachRisk safely tests whether those logins hold.

January 14, 2026ThreatsAttack surface

Exposed Signals Gateway logins and password spraying

A Signals Gateway login on the public internet is a standing target for password spraying, and one weak or reused credential turns that exposure into access. Here's the risk — and how BreachRisk safely tests whether those logins hold.

January 14, 2026ThreatsAttack surface

Exposed ServiceNow logins and password spraying

A ServiceNow login on the public internet is a standing target for password spraying, and weak or reused credentials turn that exposure into access to tickets, records, and workflows. Here's the risk — and how BreachRisk safely tests whether those logins hold.

January 14, 2026ThreatsAttack surface

Exposed Salesforce logins and password spraying

A Salesforce login on the public internet is a standing target for password spraying, and weak or reused credentials turn that exposure into access to customer and business data. Here's the risk — and how BreachRisk safely tests whether those logins hold.

January 14, 2026ThreatsAttack surface

Exposed Plesk Obsidian logins and password spraying

A Plesk Obsidian hosting control panel on the public internet is a standing target for password spraying, and one weak or reused credential turns that exposure into access. Here's the risk, and how BreachRisk safely tests whether those logins hold.

January 14, 2026ThreatsAttack surface

Exposed Parallels HTML5 Client logins and password spraying

A Parallels HTML5 Client login on the public internet is a standing target for password spraying, and one weak or reused credential can hand an attacker a remote-access gateway into your desktops and apps. Here's the risk, and how BreachRisk safely tests whether those logins hold.

January 14, 2026ThreatsAttack surface

Exposed PaperCut logins and password spraying

A PaperCut print-management login on the public internet is a standing target for password spraying, and one weak or reused credential turns that exposure into access. Here's the risk, and how BreachRisk safely tests whether those logins hold.

January 14, 2026ThreatsAttack surface

Exposed Oracle Application Server logins and password spraying

An Oracle Application Server login on the public internet is a standing target for password spraying, and one weak or reused credential turns that exposure into access. Here's the risk, and how BreachRisk safely tests whether those logins hold.

January 14, 2026ThreatsAttack surface

Exposed MiScout SCADA logins and password spraying

A MiScout SCADA login on the public internet is a standing target for password spraying, and one weak or reused credential can hand an attacker an industrial control system. Here's the risk, and how BreachRisk safely tests whether those logins hold.

January 14, 2026ThreatsAttack surface

Exposed mFusion logins and password spraying

An mFusion management login on the public internet is a standing target for password spraying, and one weak or reused credential turns that exposure into access. Here's the risk, and how BreachRisk safely tests whether those logins hold.

January 14, 2026ThreatsAttack surface

Exposed Lenel S2 logins and password spraying

A Lenel S2 access-control login on the public internet is a standing target for password spraying, and one weak or reused credential can hand an attacker your physical-security management system. Here's the risk, and how BreachRisk safely tests whether those logins hold.

January 14, 2026ThreatsAttack surface

Exposed KeyHelp logins and password spraying

A KeyHelp hosting control panel on the public internet is a standing target for password spraying, and one weak or reused credential turns that exposure into access. Here's the risk, and how BreachRisk safely tests whether those logins hold.

January 14, 2026ThreatsAttack surface

Exposed InterWorx (NodeWorx/SiteWorx) logins and password spraying

An InterWorx web hosting control panel on the public internet is a standing target for password spraying, and one weak or reused credential turns that exposure into access. Here's the risk — and how BreachRisk safely tests whether those logins hold.

January 14, 2026ThreatsApplication security

Exposed HCL Volt MX logins and password spraying

An HCL Volt MX login on the public internet is a standing target for password spraying, and weak or reused credentials turn that exposure into access to your app platform and its data. Here's the risk — and how BreachRisk safely tests whether those logins hold.

January 14, 2026ThreatsApplication security

Exposed GitLab logins and password spraying

A GitLab login on the public internet is a standing target for password spraying, and weak or reused credentials turn that exposure into access to source code, secrets, and CI/CD pipelines. Here's the risk — and how BreachRisk safely tests whether those logins hold.

January 14, 2026ThreatsAttack surface

Exposed Follett Aspen SIS logins and password spraying

A Follett Aspen student information system login on the public internet is a standing target for password spraying, and weak or reused credentials turn that exposure into access to sensitive student records. Here's the risk, and how BreachRisk safely tests whether that login holds.

January 14, 2026ThreatsAttack surface

Exposed F5 BIG-IP logins and password spraying

An F5 BIG-IP login on the public internet is a standing target for password spraying, and weak or reused credentials turn that exposure into access. Here's the risk — and how BreachRisk safely tests whether those logins hold.

January 14, 2026ThreatsAttack surface

Exposed eHealth server logins and password spraying

An eHealth server login on the public internet is a standing target for password spraying, and weak or reused credentials turn that exposure into access. Here's the risk — and how BreachRisk safely tests whether those logins hold.

January 14, 2026ThreatsAttack surface

CVE-2025-58360: GeoServer XXE file-disclosure flaw, in CISA KEV

An XML External Entity flaw in GeoServer's WMS GetMap endpoint lets an unauthenticated attacker coax the server into reading local files and reaching internal systems. It's in CISA's KEV catalog. Here's what to do, and how BreachRisk finds exposed instances.

January 14, 2026ThreatsAttack surface

CVE-2025-30406: Gladinet CentreStack hard-coded machineKey RCE, exploited as a zero-day

A hard-coded machineKey in Gladinet CentreStack lets an unauthenticated attacker forge a serialized payload and run code on the server. It was exploited as a zero-day and it's in CISA KEV. Here's what to do, and how BreachRisk finds exposed instances.

January 14, 2026ThreatsAttack surface

CVE-2025-14611: Gladinet CentreStack & Triofox hard-coded crypto, actively exploited

Gladinet CentreStack and Triofox shipped hard-coded values in their AES implementation, giving unauthenticated attackers a path to arbitrary local file inclusion. It's being exploited and it's in CISA KEV. Here's what to do, and how BreachRisk finds exposed instances.

January 14, 2026ThreatsAttack surface

CVE-2025-12480: Gladinet Triofox access-control bypass, actively exploited

An improper access-control flaw in Gladinet Triofox lets an unauthenticated attacker reach setup pages that should be locked after install — a path attackers have used in the wild to take over servers. It's in CISA KEV. Here's what to do, and how BreachRisk finds exposed instances.

January 14, 2026ThreatsAttack surface

CVE-2025-0994: Trimble Cityworks deserialization RCE, actively exploited

A deserialization flaw in Trimble Cityworks lets an authenticated user run code on the underlying IIS web server. It's been exploited in the wild against local-government systems and is in CISA's KEV catalog. Here's what to do, and how BreachRisk finds exposed instances.

January 14, 2026ThreatsAttack surface

Exposed Cerberus FTP web client logins and password spraying

A Cerberus FTP web-client login on the public internet is a standing target for password spraying, and weak or reused credentials turn that exposure into access to transferred files. Here's the risk — and how BreachRisk safely tests whether those logins hold.

January 14, 2026ThreatsCompliance

Exposed CareStar CMS logins and password spraying

A CareStar CMS login on the public internet is a standing target for password spraying, and weak or reused credentials turn that exposure into access to sensitive case-management data. Here's the risk — and how BreachRisk safely tests whether those logins hold.

January 14, 2026ThreatsAttack surface

Exposed Bomgar remote-support logins and password spraying

A Bomgar remote-support login on the public internet is a high-value target for password spraying, and one weak credential can hand an attacker privileged remote access. Here's the risk — and how BreachRisk safely tests whether those logins hold.

January 14, 2026ThreatsAttack surface

Exposed BeyondTrust Remote Support logins and password spraying

A BeyondTrust Remote Support login on the public internet is a standing target for password spraying, and weak or reused credentials turn that exposure into access to a powerful remote-support platform. Here's the risk, and how BreachRisk safely tests whether that login holds.

January 14, 2026ThreatsAttack surface

Exposed AutomatedLogic WebCTRL logins and password spraying

An AutomatedLogic WebCTRL login on the public internet is a standing target for password spraying, and weak or reused credentials turn that exposure into control of building automation systems. Here's the risk, and how BreachRisk safely tests whether that login holds.

January 14, 2026ThreatsAttack surface

Exposed atMail webmail logins and password spraying

An atMail webmail login on the public internet is a standing target for password spraying, and weak or reused credentials turn that exposure into access to a user's email. Here's the risk, and how BreachRisk safely tests whether that login holds.

January 14, 2026ThreatsAttack surface

Exposed Apache Guacamole logins and password spraying

An Apache Guacamole login on the public internet is a standing target for password spraying, and weak or reused credentials turn that exposure into a remote-desktop gateway onto your internal systems. Here's the risk, and how BreachRisk safely tests whether that login holds.

January 14, 2026ThreatsAttack surface

Exposed Adobe Experience Manager logins and password spraying

An Adobe Experience Manager login on the public internet is a standing target for password spraying, and weak or reused credentials turn that exposure into control of the platform that runs your website. Here's the risk, and how BreachRisk safely tests whether that login holds.

November 17, 2025ThreatsAttack surface

CVE-2025-64446: Fortinet FortiWeb path traversal authentication bypass, actively exploited

A relative path-traversal flaw in Fortinet FortiWeb lets an attacker bypass authentication and run administrative commands — including creating rogue admin accounts. It's in CISA KEV and actively exploited. Here's what to do, and how BreachRisk finds exposed FortiWeb.

October 24, 2025ThreatsAttack surface

CVE-2025-61884: Oracle E-Business Suite unauthenticated SSRF, in CISA KEV

An unauthenticated server-side request forgery flaw in Oracle E-Business Suite lets a remote attacker reach sensitive resources over HTTP with no login. It's in CISA's KEV catalog. Here's what to do, and how BreachRisk finds exposed EBS.

October 14, 2025ThreatsAttack surface

CVE-2025-2775: SysAid On-Prem unauthenticated XXE, chains to admin takeover

An unauthenticated XML External Entity flaw in on-premises SysAid gives attackers file-read and, chained further, administrator takeover. It's in CISA's KEV catalog; here's what to do, and how BreachRisk finds exposed servers.

October 14, 2025ThreatsAttack surface

CVE-2023-47246: SysAid On-Prem path traversal to code execution, exploited in the wild

A path-traversal flaw in on-premises SysAid let attackers write a file into the web server and run code — exploited as a zero-day by a ransomware-linked group. A fix exists; here's what to do, and how BreachRisk finds exposed servers.

October 14, 2025ThreatsAttack surface

CVE-2022-21587: Oracle E-Business Suite unauthenticated file-upload RCE, exploited

A missing-authentication flaw in Oracle E-Business Suite's upload component lets an unauthenticated attacker write files and reach remote code execution. It's in CISA's KEV catalog and exploited in the wild. Here's the risk, and how BreachRisk finds exposed EBS.

October 7, 2025ThreatsAttack surface

CVE-2025-61882: Oracle E-Business Suite unauthenticated RCE, exploited as a zero-day

An unauthenticated flaw in Oracle E-Business Suite lets an attacker run code and take over the server — exploited as a zero-day in a mass extortion campaign. It's in CISA's KEV catalog, and Oracle shipped an emergency Security Alert. Here's the risk, and how BreachRisk finds exposed EBS.

October 2, 2025ThreatsAttack surface

CVE-2024-6670: Progress WhatsUp Gold SQL injection, unauthenticated credential theft

A SQL-injection flaw in Progress WhatsUp Gold lets an unauthenticated attacker retrieve a stored, encrypted user password. It's in CISA's KEV catalog and ransomware-associated. Here's what to do, and how BreachRisk finds exposed instances.

October 2, 2025ThreatsAttack surface

CVE-2024-4885: Progress WhatsUp Gold path traversal to unauthenticated RCE

A path-traversal flaw in Progress WhatsUp Gold lets an unauthenticated attacker run commands on the monitoring server. It's in CISA's KEV catalog with a public exploit. Here's what to do, and how BreachRisk finds exposed instances.

October 2, 2025ThreatsAttack surface

CVE-2023-43208: NextGen Mirth Connect unauthenticated remote code execution

A flaw in NextGen Healthcare Mirth Connect lets an unauthenticated attacker run commands on the server — on a system that sits at the heart of healthcare data exchange. It's in CISA's KEV catalog. Here's what to do, and how BreachRisk finds exposed Mirth Connect.

September 10, 2025ThreatsApplication security

CVE-2025-55182: React Server Components unauthenticated RCE via unsafe deserialization

A deserialization flaw in React Server Components lets an unauthenticated attacker send a crafted payload to a Server Function endpoint and execute code. It's a 10.0, it's in CISA KEV, and it reaches a very large install base. Here's what to do, and how BreachRisk finds exposed apps.

September 10, 2025ThreatsAttack surface

CVE-2024-48248: NAKIVO Backup & Replication arbitrary file read, actively exploited

A file-read flaw in NAKIVO Backup & Replication lets an unauthenticated attacker read any file on the appliance — including stored, cleartext credentials that can extend an attack across the enterprise. It's in CISA's KEV catalog. Here's what to do, and how BreachRisk finds exposed NAKIVO.

September 10, 2025ThreatsApplication security

CVE-2024-26331: ReCrystallize Server authentication bypass via a spoofable cookie

ReCrystallize Server trusts a cookie value that isn't bound to a real session, so an attacker can set it and walk into the admin interface. Here's the honest risk — and how BreachRisk finds exposed ReCrystallize servers.

September 10, 2025ThreatsAttack surface

CVE-2024-2389: Progress Flowmon unauthenticated command injection, root-level RCE

A command-injection flaw in Progress Flowmon lets an unauthenticated attacker run system commands through the management interface — a 10.0 with a public exploit. Here's what to do, and how BreachRisk finds exposed appliances.

September 10, 2025ThreatsAttack surface

CVE-2023-52251: Provectus Kafka UI code injection leading to remote code execution

A code-injection flaw in the open-source Provectus Kafka UI lets an attacker run arbitrary code on the server through the message-filter parameter. Here's the honest severity, and how BreachRisk finds exposed Kafka UI instances.

September 10, 2025ThreatsApplication security

CVE-2022-36537: ZK Framework information disclosure, exploited for RCE downstream

A crafted POST to the ZK Framework's AuUploader leaks restricted internal files — and it was chained into remote code execution in products that embed ZK, like ConnectWise R1Soft. It's in CISA's KEV catalog. Here's the risk, and how BreachRisk finds and safely confirms it.

September 9, 2025ThreatsApplication security

CVE-2024-6782: Calibre content server improper access control leading to unauthenticated RCE

An access-control flaw in Calibre's content server lets an unauthenticated attacker reach privileged functionality and achieve remote code execution — a 9.8 with a public exploit. Here's what to do, and how BreachRisk finds exposed servers.

September 9, 2025ThreatsAttack surface

CVE-2021-20124: DrayTek VigorConnect path traversal in WebServlet, unauthenticated root file read, in CISA KEV

A second path-traversal flaw in DrayTek VigorConnect — this one in the WebServlet endpoint — lets an unauthenticated attacker read arbitrary files as root. A 7.5 in CISA's KEV catalog. Here's what it exposes, and how BreachRisk finds affected systems.

September 9, 2025ThreatsAttack surface

CVE-2021-20123: DrayTek VigorConnect path traversal, unauthenticated root file read, in CISA KEV

A path-traversal flaw in DrayTek VigorConnect's DownloadFileServlet lets an unauthenticated attacker read arbitrary files as root — a 7.5 that's in CISA's KEV catalog. Here's what it exposes, and how BreachRisk finds affected systems.

September 3, 2025ThreatsAttack surface

CVE-2021-39226: Grafana snapshot authentication bypass, actively exploited

A flaw in Grafana lets unauthenticated users view dashboard snapshots by walking predictable paths — exposing whatever those snapshots contain. It's in CISA KEV with near-certain exploitation activity. Here's what to do, and how BreachRisk finds exposed instances.

September 3, 2025ThreatsAttack surface

CVE-2021-36260: Hikvision unauthenticated command injection, actively exploited

A command-injection flaw in the web server of many Hikvision products lets an unauthenticated attacker run commands on the device. It's in CISA KEV with widespread exploitation. Here's what to do, and how BreachRisk finds exposed cameras.

September 3, 2025ThreatsAttack surface

CVE-2021-35464: ForgeRock AM (OpenAM) unauthenticated Java deserialization RCE, ransomware-exploited

A Java deserialization flaw in ForgeRock AM lets an unauthenticated attacker run code with a single crafted request — a 9.8, exploited by ransomware operators, and in CISA's KEV catalog. Here's what to do, and how BreachRisk finds exposed identity gateways.

September 2, 2025ThreatsAttack surface

CVE-2021-44515: Zoho ManageEngine Desktop Central auth bypass to RCE, actively exploited

An authentication bypass in ManageEngine Desktop Central lets an attacker skip login and execute code on the endpoint-management server — exploited in the wild and in CISA KEV. Here's what to do, and how BreachRisk finds and safely confirms exposed Desktop Central.

September 2, 2025ThreatsAttack surface

CVE-2021-44077: Zoho ManageEngine ServiceDesk Plus unauthenticated RCE, actively exploited

A missing-authentication flaw in ManageEngine ServiceDesk Plus lets an attacker upload files and drop a web shell for unauthenticated remote code execution — exploited by APT actors and in CISA KEV. Here's what to do, and how BreachRisk finds and safely confirms exposed ServiceDesk Plus.

August 8, 2025ThreatsAttack surface

Exposed Active! mail logins and password spraying

An Active! mail webmail login on the public internet is a standing target for password spraying, and weak or reused credentials turn that exposure into access to a user's email. Here's the risk, and how BreachRisk safely tests whether that login holds.

August 4, 2025ThreatsAttack surface

Exposed Sophos VPN and firewall logins and password spraying

A Sophos VPN or firewall login on the public internet is a standing target for password spraying, and weak or reused credentials turn that exposure into VPN access to your network. Here's the risk, and how BreachRisk safely tests whether those logins hold.

August 4, 2025ThreatsApplication security

CVE-2023-2533: PaperCut NG/MF cross-site request forgery, now actively exploited

A cross-site request forgery flaw in PaperCut NG/MF can let an attacker ride a logged-in admin's session to change security settings — or reach code execution. It sat quietly until CISA added it to KEV. Here's what to do, and how BreachRisk finds exposed PaperCut consoles.

July 30, 2025ThreatsAttack surface

CVE-2025-4632: Samsung MagicINFO 9 Server path traversal, patch-bypass exploited in the wild

A path-traversal flaw in Samsung MagicINFO 9 Server lets an unauthenticated attacker write files with system authority — and it bypasses the earlier fix for CVE-2024-7399. It's in CISA's KEV catalog and exploited by botnets. Here's what to do, and how BreachRisk finds exposed servers.

July 25, 2025ThreatsAttack surface

Exposed Roundcube webmail logins and password spraying

A Roundcube webmail login on the public internet is a standing target for password spraying, and one weak or reused credential turns that exposure into access to a live mailbox. Here's the risk — and how BreachRisk safely tests whether those logins hold.

July 25, 2025ThreatsAttack surface

Exposed Redmine logins and password spraying

A Redmine project portal on the public internet is a standing target for password spraying, and weak or reused credentials turn that exposure into access to your projects, issues, and files. Here's the risk — and how BreachRisk safely tests whether those logins hold.

July 25, 2025ThreatsAttack surface

Exposed EasyPanel logins and password spraying

An EasyPanel login on the public internet is a standing target for password spraying, and weak or reused credentials turn that exposure into control of your deployed applications and servers. Here's the risk — and how BreachRisk safely tests whether those logins hold.

July 25, 2025ThreatsAttack surface

Exposed cPanel logins and password spraying

A cPanel login on the public internet is a standing target for password spraying, and weak or reused credentials turn that exposure into control of a hosting account. Here's the risk — and how BreachRisk safely tests whether those logins hold.

July 23, 2025ThreatsAttack surface

CVE-2025-5777 (Citrix Bleed 2): NetScaler memory over-read that leaks session material

"Citrix Bleed 2" leaks memory from NetScaler ADC/Gateway to an unauthenticated attacker — echoing the original CitrixBleed, where leaked session material meant hijacked sessions. NVD calls it a 7.5; the real world treats it as far worse. Here's why, and how BreachRisk finds exposed appliances.

July 23, 2025ThreatsAttack surface

CVE-2023-38950: ZKTeco BioTime path traversal, unauthenticated file read, in CISA KEV

A path-traversal flaw in ZKTeco BioTime lets an unauthenticated attacker read arbitrary files off the server — a 7.5 that's in CISA's KEV catalog. Here's what it exposes, and how BreachRisk finds affected systems.

July 22, 2025ThreatsAttack surface

CVE-2025-6543: Citrix NetScaler memory overflow, unauthenticated and exploited in the wild

A memory-overflow flaw in NetScaler ADC and Gateway causes unintended control flow and denial of service when the device is a Gateway or AAA server — exploited as a zero-day and in CISA's KEV catalog. Here's what to do, and how BreachRisk finds exposed NetScalers.

July 22, 2025ThreatsAttack surface

CVE-2025-47812: Wing FTP Server null-byte flaw to root/SYSTEM RCE, exploited in the wild

A null-byte handling flaw in Wing FTP Server lets an attacker inject code and execute commands as root or SYSTEM — even via an anonymous account. It's exploited in the wild and in CISA's KEV catalog. Here's what to do, and how BreachRisk finds exposed servers.

July 22, 2025ThreatsAttack surface

CVE-2025-42999: SAP NetWeaver Visual Composer deserialization, exploited in the wild

An insecure-deserialization flaw in SAP NetWeaver Visual Composer was chained with a companion upload bug and used in real attacks on internet-facing SAP systems. It's in CISA KEV. Here's what to do, and how BreachRisk finds exposed NetWeaver instances.

July 22, 2025ThreatsAttack surface

CVE-2024-57727: SimpleHelp unauthenticated path traversal, actively exploited

A path-traversal flaw in SimpleHelp lets an unauthenticated attacker download server files — including the configuration file with secrets and hashed passwords. It's the entry point of a takeover chain, it's mass-exploited, and it's in CISA KEV. Here's what to do, and how BreachRisk finds exposed SimpleHelp servers.

May 29, 2025ThreatsAttack surface

CVE-2022-29464: WSO2 unrestricted file upload to unauthenticated RCE

An unrestricted file-upload flaw across several WSO2 products lets an unauthenticated attacker drop a web shell and run code. It's in CISA's KEV catalog, ransomware-associated, and mass-exploited. Here's what to do, and how BreachRisk finds exposed instances.

May 29, 2025ThreatsAttack surface

CVE-2022-29303: SolarView Compact unauthenticated command injection, actively exploited

A command-injection flaw in Contec SolarView Compact solar-monitoring devices lets an unauthenticated attacker run OS commands via conf_mail.php. It's a 9.8, botnets have used it, and it's in CISA KEV. Here's what to do, and how BreachRisk finds exposed SolarView devices.

May 29, 2025ThreatsApplication security

CVE-2022-27926: Zimbra Collaboration reflected XSS, exploited by nation-state actors

A reflected cross-site scripting flaw in Zimbra Collaboration's webmail lets an attacker run script in a victim's session with one crafted link — and it was used against government targets. Here's the risk, and how BreachRisk finds and safely confirms exposed Zimbra.

May 29, 2025ThreatsAttack surface

CVE-2022-24990: TerraMaster NAS admin-password disclosure, a step to full compromise

A flaw in TerraMaster NAS leaks the administrative password to an unauthenticated request — and chained with a second bug, it becomes remote code execution. It's ransomware-associated and in CISA's KEV catalog. Here's what to do, and how BreachRisk finds exposed devices.

May 29, 2025ThreatsAttack surface

CVE-2022-23134: Zabbix Frontend setup.php improper access control

A weak access check in the Zabbix Frontend setup process lets an unauthenticated user reach configuration steps meant for administrators. It's in CISA's KEV catalog. Here's the honest severity, and how BreachRisk finds exposed instances.

May 29, 2025ThreatsAttack surface

CVE-2022-22954: VMware Workspace ONE Access unauthenticated remote code execution

A server-side template injection in VMware Workspace ONE Access and Identity Manager lets an unauthenticated attacker run code on the server. A 9.8, in CISA KEV, exploited in the wild. Here's what to do, and how BreachRisk finds exposed instances.

May 28, 2025ThreatsAttack surface

CVE-2023-41266: Qlik Sense path traversal that mints an anonymous session

A path-traversal flaw in Qlik Sense Enterprise for Windows lets an unauthenticated attacker generate an anonymous session and reach restricted endpoints — the first link in a chain that ransomware operators used for full compromise. Here's what to do, and how BreachRisk finds exposed Qlik servers.

May 28, 2025ThreatsAttack surface

CVE-2023-32315: Openfire admin console path traversal, actively exploited

A path-traversal flaw in Openfire's admin console lets an unauthenticated attacker reach restricted admin pages — a known stepping stone to plugin-upload code execution. It's in CISA's KEV catalog. Here's what to do, and how BreachRisk finds exposed Openfire.

May 28, 2025ThreatsAttack surface

CVE-2023-27350: PaperCut NG/MF authentication bypass to remote code execution, actively exploited

A flaw in PaperCut NG/MF lets an unauthenticated attacker bypass authentication and run code as SYSTEM. It was exploited in the wild, including by ransomware operators, and it's in CISA's KEV catalog. Here's what to do, and how BreachRisk finds exposed PaperCut.

May 27, 2025ThreatsAttack surface

CVE-2023-49103: ownCloud graphapi credential disclosure, actively exploited

A flaw in the ownCloud graphapi app exposes the server's PHP environment — and in containerized deployments that includes the admin password and other secrets — to an unauthenticated request. It's in CISA's KEV catalog. Here's what to do, and how BreachRisk finds exposed ownCloud.

May 27, 2025ThreatsAttack surface

CVE-2023-42793: JetBrains TeamCity authentication bypass to RCE, exploited by ransomware and APTs

An authentication bypass in JetBrains TeamCity lets an unauthenticated attacker run code on the CI/CD server. It's in CISA KEV, used in ransomware and nation-state campaigns. Here's what to do, and how BreachRisk finds exposed servers.

May 27, 2025ThreatsAttack surface

CVE-2023-35082: Ivanti EPMM / MobileIron Core authentication bypass, actively exploited

A second authentication bypass in Ivanti Endpoint Manager Mobile — reaching back into older MobileIron Core releases — lets a remote, unauthenticated attacker hit protected API endpoints. It's a perfect 10.0, exploited in the wild and in CISA's KEV catalog. Here's what to do, and how BreachRisk finds exposed servers.

May 27, 2025ThreatsAttack surface

CVE-2023-35078: Ivanti EPMM (MobileIron) authentication bypass, actively exploited

An authentication bypass in Ivanti Endpoint Manager Mobile (formerly MobileIron Core) lets a remote, unauthenticated attacker reach protected API endpoints — including user and device data. It's a perfect 10.0, exploited in the wild and in CISA's KEV catalog. Here's what to do, and how BreachRisk finds exposed servers.

May 27, 2025ThreatsAttack surface

CVE-2023-28432: MinIO information disclosure that leaks admin credentials

A flaw in clustered MinIO deployments returns all environment variables — including the root user and password — to an unauthenticated request. It's in CISA's KEV catalog. Here's why an information leak here is worse than it sounds, and how BreachRisk finds exposed MinIO.

May 27, 2025ThreatsAttack surface

CVE-2022-35914: GLPI unauthenticated command execution, actively exploited

A bundled test endpoint in GLPI lets an unauthenticated attacker inject PHP and run commands on the server. It's in CISA KEV with near-certain exploitation activity. Here's what to do, and how BreachRisk finds exposed instances.

May 27, 2025Threats

Exposed Cerbo patient-portal logins and password spraying

A Cerbo patient-portal login on the public internet is a standing target for password spraying, and weak or reused credentials turn that exposure into access to protected health information. Here's the risk — and how BreachRisk safely tests whether those logins hold.

May 23, 2025ThreatsAttack surface

CVE-2023-43177: CrushFTP unauthenticated command execution via attacker-controlled attributes

A flaw in CrushFTP lets an unauthenticated attacker manipulate object attributes to reach control of the server. It scores 9.8 and file-transfer servers are prime targets — though it isn't currently in CISA's KEV catalog. Here's the honest read, and how BreachRisk finds exposed CrushFTP servers.

May 23, 2025ThreatsApplication security

CVE-2023-22527: Atlassian Confluence template injection to unauthenticated RCE, actively exploited

A template-injection flaw in out-of-date Confluence Data Center and Server lets an unauthenticated attacker run code on the instance. It's in CISA's KEV catalog and tied to ransomware. Here's what to do, and how BreachRisk finds exposed Confluence.

May 23, 2025ThreatsApplication security

CVE-2022-36804: Atlassian Bitbucket command injection, remote code execution, actively exploited

A command-injection flaw in Bitbucket Server and Data Center lets an attacker with read access to a repository — public or private — run code by sending a crafted request. It's in CISA's KEV catalog. Here's what to do, and how BreachRisk finds exposed Bitbucket.

May 23, 2025ThreatsApplication security

CVE-2022-26138: Atlassian Questions for Confluence hard-coded password, actively exploited

The Questions for Confluence app creates a hidden account with a hard-coded, now-public password — handing any unauthenticated attacker a login. It's in CISA's KEV catalog. Here's what to do, and how BreachRisk finds exposed Confluence.

May 22, 2025ThreatsApplication security

CVE-2023-49070: Apache OFBiz pre-auth remote code execution via legacy XML-RPC

Leftover XML-RPC code in Apache OFBiz gives an unauthenticated attacker a path to remote code execution. It's a critical-class flaw in an ERP platform. Here's what to do, and how BreachRisk finds exposed OFBiz.

May 22, 2025ThreatsApplication security

CVE-2023-38205: Adobe ColdFusion access-control bypass (the patch-bypass fix), actively exploited

This is the flaw that let attackers slip past the first fix for ColdFusion's access-control bypass and keep reaching administrator endpoints — exploited in the wild and in CISA's KEV catalog. Here's what to do, and how BreachRisk finds exposed ColdFusion servers.

May 22, 2025ThreatsApplication security

CVE-2023-29300: Adobe ColdFusion unauthenticated deserialization RCE, actively exploited

A deserialization flaw in Adobe ColdFusion lets an unauthenticated attacker run arbitrary code on the server — a 9.8, exploited in the wild to drop web shells, and in CISA's KEV catalog. Here's what to do, and how BreachRisk finds exposed ColdFusion servers.

May 22, 2025ThreatsApplication security

CVE-2023-29298: Adobe ColdFusion access-control bypass, actively exploited

An access-control bypass in Adobe ColdFusion lets an unauthenticated attacker reach administrator endpoints — and in the wild it was the front half of an exploit chain that dropped web shells. It's in CISA's KEV catalog. Here's what to do, and how BreachRisk finds exposed ColdFusion servers.

May 22, 2025ThreatsApplication security

CVE-2023-27524: Apache Superset default SECRET_KEY authentication bypass, actively exploited

Apache Superset instances left on the default SECRET_KEY let an attacker forge their own session cookies and log in as any user — often the path to full takeover. It's in CISA's KEV catalog. Here's what to do, and how BreachRisk finds exposed Superset.

May 22, 2025ThreatsAttack surface

CVE-2023-26360: Adobe ColdFusion unauthenticated file read and code execution, actively exploited

An access-control flaw in Adobe ColdFusion lets an unauthenticated attacker read sensitive files and run code — it's in CISA's KEV catalog and was used to breach government servers. Here's what to do, and how BreachRisk finds exposed ColdFusion.

May 22, 2025ThreatsAttack surface

CVE-2022-33891: Apache Spark UI command injection via user impersonation, actively exploited

When ACLs are enabled, a flaw in the Apache Spark UI lets an attacker impersonate an arbitrary user and run shell commands as the Spark process. It's in CISA's KEV catalog. Here's what to do, and how BreachRisk finds exposed Spark UIs.

May 22, 2025ThreatsAttack surface

CVE-2022-24706: Apache CouchDB insecure default leads to unauthenticated admin and RCE

An insecure default in Apache CouchDB lets an attacker reach an improperly secured install without authenticating and escalate to admin — and, via Erlang, to code execution. A 9.8 in CISA's KEV catalog. Here's what to do, and how BreachRisk finds exposed nodes.

May 22, 2025ThreatsAttack surface

CVE-2022-24112: Apache APISIX Admin API bypass leading to remote code execution, actively exploited

A batch-requests flaw in Apache APISIX lets an attacker bypass the Admin API's IP restriction and, with the default admin key, reach unauthenticated remote code execution. It's in CISA's KEV catalog. Here's what to do, and how BreachRisk finds exposed gateways.

May 9, 2025ThreatsAttack surface

CVE-2024-29824: Ivanti Endpoint Manager SQL injection to code execution, in CISA KEV

An unauthenticated SQL injection in the Ivanti Endpoint Manager core server lets an attacker on the same network run arbitrary commands on the box that manages your endpoints. It's in CISA's KEV catalog. Here's what to do, and how BreachRisk finds exposed EPM servers.

May 9, 2025ThreatsAttack surface

CVE-2024-13160: Ivanti Endpoint Manager path traversal and credential coercion, unauthenticated

An absolute path-traversal flaw in Ivanti Endpoint Manager lets a remote, unauthenticated attacker leak sensitive data — and researchers showed it can coerce the EPM machine-account credential. It's one of three related CVEs, all in CISA's KEV catalog. Here's what to do, and how BreachRisk finds exposed servers.

May 9, 2025ThreatsAttack surface

CVE-2024-10914: D-Link NAS command injection on end-of-life devices D-Link won't patch

A command-injection flaw in several end-of-life D-Link NAS models lets an attacker inject OS commands via the account-management endpoint — and D-Link won't fix it. The only real remedy is retirement. Here's the risk, and how BreachRisk finds exposed devices.

May 8, 2025ThreatsAttack surface

CVE-2024-53704: SonicWall SonicOS SSLVPN authentication bypass, actively exploited

An authentication-bypass flaw in SonicWall's SSLVPN lets a remote attacker step past login with a crafted session cookie. A public exploit exists and it's being used. It's in CISA's KEV catalog. Here's what to do, and how BreachRisk finds and safely confirms exposed firewalls.

May 8, 2025ThreatsApplication security

CVE-2024-38819: Spring Framework path traversal in functional static-resource routes

A path-traversal flaw in Spring Framework can let an attacker read files off the server — but only when an app serves static resources through the functional web frameworks in a specific way. Here's who's actually affected, and how BreachRisk checks.

May 8, 2025ThreatsAttack surface

CVE-2024-29973: Zyxel NAS unauthenticated command injection, exploited by botnets

A command-injection flaw in Zyxel NAS326 and NAS542 lets an unauthenticated attacker run OS commands with a crafted HTTP request — on end-of-life devices already being swept up by botnets. Here's the risk, and how BreachRisk finds and safely confirms exposed NAS.

May 8, 2025ThreatsApplication security

CVE-2024-29895: Cacti unauthenticated command injection in the 1.3.x dev branch

A command-injection flaw in Cacti's development branch lets an unauthenticated attacker run OS commands — a 10.0 on paper, but it only affects the unreleased 1.3.x dev code. Here's the real risk, and how BreachRisk finds exposed Cacti.

May 7, 2025ThreatsApplication security

CVE-2025-32432: Craft CMS unauthenticated remote code execution, exploited in the wild

An unauthenticated remote code execution flaw in Craft CMS — a perfect 10.0 — was exploited in the wild before many sites patched. It's in CISA's KEV catalog. Here's what to do, and how BreachRisk finds exposed Craft installs.

May 7, 2025ThreatsAttack surface

CVE-2025-31161: CrushFTP authentication bypass and admin account takeover

An authentication-bypass flaw in CrushFTP lets an unauthenticated attacker take over the crushadmin account and, with it, the file server. A 9.8, in CISA KEV, exploited in the wild. Here's what to do, and how BreachRisk finds exposed servers.

May 7, 2025ThreatsApplication security

CVE-2025-28367: mojoPortal directory traversal exposing Web.config and the machine key

A directory-traversal flaw in mojoPortal lets an unauthenticated attacker read the Web.config file and lift the ASP.NET machine key. Here's why that matters more than a file read, and how BreachRisk finds exposed mojoPortal.

May 7, 2025ThreatsAttack surface

CVE-2024-9465: Palo Alto Expedition unauthenticated SQL injection, actively exploited

An unauthenticated SQL injection in Palo Alto's Expedition migration tool lets an attacker dump password hashes, usernames, and device API keys — the keys to your firewalls. It's in CISA KEV. Here's what to do, and how BreachRisk finds exposed Expedition.

May 7, 2025ThreatsAttack surface

CVE-2024-8963: Ivanti Cloud Services Appliance path traversal, unauthenticated and exploited

A path-traversal flaw in the Ivanti Cloud Services Appliance lets an unauthenticated attacker reach restricted functionality — and chained with a companion bug it enabled remote code execution. It's in CISA's KEV catalog. Here's what to do, and how BreachRisk finds exposed appliances.

May 7, 2025ThreatsApplication security

CVE-2024-56145: Craft CMS remote code execution via register_argc_argv

A remote code execution flaw in Craft CMS affects sites whose PHP has register_argc_argv enabled — a common default. It's in CISA's KEV catalog and being exploited. Here's what to do, and how BreachRisk finds exposed Craft installs.

May 7, 2025ThreatsApplication security

CVE-2024-4879 (with CVE-2024-5217): ServiceNow Now Platform unauthenticated RCE, actively exploited

Input-validation flaws in the ServiceNow Now Platform let an unauthenticated attacker inject Jelly template code and execute commands. The pair was mass-exploited after disclosure and both are in CISA KEV. Here's what to do, and how BreachRisk finds exposed ServiceNow instances.

May 7, 2025ThreatsApplication security

CVE-2024-46938: Sitecore unauthenticated arbitrary file read

A path-traversal flaw in Sitecore XP/XM/XC lets an unauthenticated attacker read arbitrary files — including web.config, whose secrets can be turned into remote code execution via ViewState. Here's what to do, and how BreachRisk finds exposed Sitecore servers.

May 7, 2025ThreatsApplication security

CVE-2024-4358: Progress Telerik Report Server authentication bypass, actively exploited

An unauthenticated attacker can bypass authentication on Progress Telerik Report Server and reach restricted functionality — and it's been chained to remote code execution. It's in CISA KEV. Here's what to do, and how BreachRisk finds exposed servers.

May 7, 2025ThreatsAttack surface

CVE-2024-41713: Mitel MiCollab path traversal, actively exploited

A path-traversal flaw in Mitel MiCollab lets an unauthenticated attacker read files and reach data and configuration they shouldn't. It's in CISA's KEV catalog and ransomware-associated. Here's what to do, and how BreachRisk finds exposed MiCollab.

May 7, 2025ThreatsAttack surface

CVE-2024-36991: Splunk Enterprise on Windows path traversal, unauthenticated file read

A path-traversal flaw in Splunk Enterprise on Windows lets an unauthenticated attacker read files off the server — including material that can lead to account access. A fix exists; here's what to check, and how BreachRisk finds exposed instances.

May 7, 2025ThreatsAttack surface

CVE-2024-35286: Mitel MiCollab SQL injection, unauthenticated

A SQL-injection flaw in Mitel MiCollab lets an unauthenticated attacker read sensitive data and run database and management operations. Here's what to do, and how BreachRisk finds exposed MiCollab.

May 7, 2025ThreatsAttack surface

CVE-2024-20440: Cisco Smart Licensing Utility log leaks credentials to unauthenticated attackers

An overly verbose debug log in Cisco's Smart Licensing Utility can be pulled by an unauthenticated attacker — and it contains credentials that unlock the API. It pairs naturally with the CSLU static-credential flaw. Here's the risk, and how BreachRisk finds exposed instances.

May 7, 2025ThreatsAttack surface

CVE-2024-20439: Cisco Smart Licensing Utility static-credential backdoor, actively exploited

Cisco's Smart Licensing Utility shipped with an undocumented static admin credential — anyone who knows it can log into the API with full rights. It's in CISA's KEV catalog and being exploited. Here's what to do, and how BreachRisk finds exposed instances.

May 7, 2025ThreatsAttack surface

CVE-2024-1212: Progress Kemp LoadMaster unauthenticated OS command injection, actively exploited

An unauthenticated attacker who can reach the Progress Kemp LoadMaster management interface can run arbitrary system commands — potentially as root. It scores a 10 and is in CISA KEV. Here's what to do, and how BreachRisk finds exposed LoadMasters.

May 7, 2025ThreatsApplication security

CVE-2024-11680: ProjectSend unauthenticated authentication bypass, actively exploited

An improper-authentication flaw in ProjectSend lets an unauthenticated attacker change the app's configuration, create accounts, and plant web shells. It's a 9.8, mass-exploited, and in CISA KEV. Here's what to do, and how BreachRisk finds exposed ProjectSend instances.

May 6, 2025ThreatsApplication security

CVE-2024-45507: Apache OFBiz unauthenticated remote code execution

A missing-authorization flaw in Apache OFBiz lets an unauthenticated attacker reach code injection and SSRF — a critical, network-reachable path into an ERP platform. Here's what to do, and how BreachRisk finds exposed OFBiz.

May 6, 2025ThreatsApplication security

CVE-2024-45195: Apache OFBiz forced-browsing patch bypass to remote code execution, actively exploited

A forced-browsing flaw in Apache OFBiz bypasses earlier patches to reach restricted functionality — and, in practice, code execution. NVD scores it 7.5; the real world put it in KEV. Here's why, and how BreachRisk finds exposed OFBiz.

May 6, 2025ThreatsApplication security

CVE-2024-38856: Apache OFBiz authorization bypass to remote code execution, actively exploited

An incorrect-authorization flaw in Apache OFBiz lets an unauthenticated attacker reach screen-rendering code and execute commands — it's in CISA's KEV catalog with public exploits. Here's what to do, and how BreachRisk finds exposed OFBiz.

May 6, 2025ThreatsAttack surface

CVE-2024-20767: Adobe ColdFusion arbitrary file read via exposed admin panel, actively exploited

An access-control flaw in Adobe ColdFusion lets an unauthenticated attacker read arbitrary files when the admin panel is internet-exposed — it's in CISA's KEV catalog with a public proof-of-concept. Here's what to do, and how BreachRisk finds exposed ColdFusion.

May 5, 2025ThreatsAttack surface

Exposed SMB file sharing on the public internet

An SMB service exposed to the public internet is a standing target for credential attacks and a protocol that was never meant to face the open internet. Here's the risk, and how BreachRisk safely tests whether those credentials hold.

May 5, 2025ThreatsAttack surface

Exposed Apache Tomcat Manager logins and password spraying

An Apache Tomcat Manager login on the public internet is a high-value target for password spraying — a working credential can mean deploying code and full server compromise. Here's the risk, and how BreachRisk safely tests whether that login holds.

May 2, 2025ThreatsApplication security

CVE-2024-4956: Sonatype Nexus Repository path traversal, unauthenticated file read

A path-traversal flaw in Sonatype Nexus Repository 3 lets an unauthenticated attacker read system files — with a public exploit and easy discovery. Here's what to do, and how BreachRisk finds and safely confirms exposed servers.

May 2, 2025ThreatsApplication security

CVE-2024-31982: XWiki unauthenticated remote code execution via database search

A code-injection flaw in XWiki's database search lets any visitor run code on the server through the search text — no login required. It's a 9.8 with a public exploit. Here's what to do, and how BreachRisk finds and safely confirms exposed XWiki.

May 2, 2025ThreatsAttack surface

CVE-2024-1709: ConnectWise ScreenConnect authentication bypass, mass-exploited

An authentication-bypass flaw in ConnectWise ScreenConnect lets an unauthenticated attacker walk into the admin setup and create an administrator — a perfect 10.0, mass-exploited within days. Here's what to do, and how BreachRisk finds exposed ScreenConnect servers.

May 2, 2025ThreatsAttack surface

CVE-2022-1040: Sophos Firewall authentication bypass to RCE, exploited in the wild

An authentication-bypass flaw in Sophos Firewall's User Portal and Webadmin lets a remote attacker reach code execution, and it was exploited as a targeted zero-day. It's in CISA's KEV catalog. Here's what to do, and how BreachRisk finds and safely confirms exposed firewalls.

May 1, 2025ThreatsAttack surface

Exposed Nexus smart-meter logins and password spraying

A Nexus smart-meter login on the public internet is a standing target for password spraying, and weak or reused credentials turn that exposure into access to an internet-facing metering device. Here's the risk — and how BreachRisk safely tests whether those logins hold.

May 1, 2025ThreatsAttack surface

CVE-2024-23897: Jenkins Path Traversal Vulnerability Exploitation (CVE-2024-23897)

Jenkins 2.441 and earlier, LTS 2.426.2 and earlier does not disable a feature of its CLI command parser that replaces an '@' character followed by a file path in an argument with the file's contents, allowing unauthentic…

May 1, 2025ThreatsAttack surface

Exposed Hikvision router logins and password spraying

A Hikvision router login on the public internet is a standing target for password spraying, and weak or default credentials turn that exposure into control of a network device. Here's the risk, and how BreachRisk safely tests whether that login holds.

May 1, 2025ThreatsAttack surface

Exposed Hikvision IP camera logins and password spraying

A Hikvision IP camera login on the public internet is a standing target for password spraying, and weak or default credentials turn that exposure into a live view of your premises. Here's the risk, and how BreachRisk safely tests whether that login holds.

May 1, 2025ThreatsAttack surface

CVE-2024-7593: Ivanti Virtual Traffic Manager authentication bypass, admin takeover

A broken authentication algorithm in Ivanti Virtual Traffic Manager lets a remote, unauthenticated attacker bypass the admin panel and create a rogue administrator. It's in CISA's KEV catalog with a public exploit. Here's what to do, and how BreachRisk finds exposed appliances.

May 1, 2025ThreatsAttack surface

CVE-2024-50623: Cleo Harmony, VLTrader & LexiCom unrestricted file upload RCE, ransomware-exploited

An unrestricted file-upload flaw in Cleo's managed-file-transfer products lets an unauthenticated attacker upload and run code — a 9.8, exploited at scale by ransomware crews, and in CISA's KEV catalog. Here's what to do, and how BreachRisk finds exposed servers.

May 1, 2025ThreatsApplication security

CVE-2024-37383: Roundcube Webmail cross-site scripting, exploited in government phishing

A cross-site scripting flaw via SVG animate attributes lets a crafted email run script in a Roundcube user's session. It's in CISA's KEV catalog and was used in phishing against government agencies. Here's the risk, and how BreachRisk finds exposed Roundcube instances.

May 1, 2025ThreatsApplication security

CVE-2024-31849: CData Connect path traversal, unauthenticated admin access

A path-traversal flaw in the Java build of CData Connect running on the embedded Jetty server lets an unauthenticated attacker reach administrative functionality. Rated 9.8 by the reporting researcher. Here's what to do, and how BreachRisk finds exposed CData.

May 1, 2025ThreatsAttack surface

CVE-2024-23692: Rejetto HTTP File Server unauthenticated RCE, actively exploited

A template-injection flaw in Rejetto HTTP File Server (HFS) 2.3m and earlier lets an unauthenticated attacker run commands with a single crafted request. It's exploited in the wild, it's in CISA KEV, and the affected version is end-of-life. Here's what to do, and how BreachRisk finds exposed HFS servers.

May 1, 2025ThreatsAttack surface

CVE-2024-0204: Fortra GoAnywhere MFT authentication bypass, create-admin flaw

An authentication bypass in Fortra's GoAnywhere MFT lets an unauthenticated attacker create a new administrator account through the admin portal. It scores 9.8 and has public exploits. Here's what to do, and how BreachRisk finds exposed GoAnywhere.

May 1, 2025ThreatsAttack surface

CVE-2023-0669: Fortra GoAnywhere MFT deserialization RCE — the Clop mass-exploitation flaw

A deserialization flaw in GoAnywhere MFT's License Response Servlet gave attackers remote code execution — and the Clop ransomware group used it as a zero-day to steal data from scores of organizations. NVD rates it 7.2; the real world made it far worse. Here's why, and how BreachRisk finds exposed GoAnywhere.

May 1, 2025ThreatsApplication security

CVE-2022-26134: Atlassian Confluence OGNL injection, unauthenticated RCE, exploited as a zero-day

A second OGNL injection flaw in Confluence Server and Data Center — this one exploited as a zero-day before the patch. Unauthenticated, remote, code execution, a 9.8, and in CISA's KEV catalog. Here's what to do, and how BreachRisk finds exposed Confluence.

May 1, 2025ThreatsAttack surface

CVE-2021-41773: Apache HTTP Server path traversal, actively exploited

A path-traversal flaw in a single Apache HTTP Server release lets attackers read files outside the web root and, where CGI is enabled, run code. It's in CISA's KEV catalog and tied to ransomware. Here's what to do, and how BreachRisk finds affected servers.

May 1, 2025ThreatsAttack surface

CVE-2021-33558: Boa web server information disclosure (disputed)

An information-disclosure issue reported against the Boa web server — but disputed, and Boa itself is long unmaintained and common in embedded devices. Here's the honest picture, and how BreachRisk finds exposed Boa on your attack surface.

May 1, 2025ThreatsApplication security

CVE-2021-26084: Atlassian Confluence OGNL injection, unauthenticated RCE, actively exploited

An OGNL injection flaw in Confluence Server and Data Center lets an unauthenticated attacker run code on the server. It's a 9.8, it's in CISA's KEV catalog, and it was mass-exploited for coin miners and ransomware. Here's what to do, and how BreachRisk finds exposed Confluence.

May 1, 2025ThreatsAttack surface

CVE-2021-20021: SonicWall Email Security admin-account creation, actively exploited

A flaw in SonicWall Email Security lets an unauthenticated attacker create an administrator account with a single crafted request, and it was chained as a zero-day by ransomware actors. It's in CISA's KEV catalog. Here's what to do, and how BreachRisk finds exposed appliances.

May 1, 2025ThreatsAttack surface

CVE-2019-7481: SonicWall SMA100 SQL injection, unauthenticated data access

A SQL-injection flaw in SonicWall SMA100 lets an unauthenticated attacker read data they shouldn't, and it's tied to ransomware campaigns against these appliances. It's in CISA's KEV catalog. Here's what to do, and how BreachRisk finds and safely confirms exposed devices.

May 1, 2025ThreatsAttack surface

CVE-2018-13382: Fortinet FortiOS SSL VPN improper authorization — vendor-disputed

A reported authorization flaw in the FortiOS SSL VPN portal — the so-called 'magic backdoor' — that Fortinet has publicly disputed. Only old, mostly end-of-life FortiOS is affected. Here's an honest read on the evidence, and how BreachRisk finds exposed FortiGates.

May 1, 2025ThreatsAttack surface

CVE-2014-6271 (Shellshock): Bash command injection on exposed SonicWall appliances

Shellshock is a decade-old Bash flaw that still turns up on legacy appliances, letting an unauthenticated attacker run commands via a crafted request. It's in CISA's KEV catalog. Here's what to do, and how BreachRisk finds and safely confirms exposed SonicWall devices.

April 30, 2025ThreatsAttack surface

CVE-2025-31324: SAP NetWeaver Visual Composer unauthenticated file upload to RCE, actively exploited

A missing authorization check in SAP NetWeaver's Visual Composer lets an unauthenticated attacker upload an executable and take over the host — a perfect 10.0, exploited in the wild. Here's what to do, and how BreachRisk finds and safely verifies exposed NetWeaver.

April 30, 2025ThreatsAttack surface

CVE-2022-21371: Oracle WebLogic path traversal that leaks internal files

A path-traversal flaw in Oracle WebLogic lets an unauthenticated attacker read deployment descriptors and other internal files — no takeover, but the leaked config can enable the next attack. Here's the honest severity, and how BreachRisk finds and safely confirms exposed WebLogic.

April 30, 2025ThreatsAttack surface

CVE-2022-1388: F5 BIG-IP iControl REST authentication bypass, unauthenticated RCE

An authentication-bypass flaw in F5 BIG-IP's iControl REST interface lets an unauthenticated attacker run commands as root. It scores 9.8, has public exploits, and is in CISA's KEV catalog with ransomware use. Here's what to do, and how BreachRisk finds exposed BIG-IP devices.

April 30, 2025ThreatsAttack surface

CVE-2021-35587: Oracle Access Manager unauthenticated takeover, actively exploited

A missing-authentication flaw in Oracle Access Manager lets an unauthenticated attacker take over the SSO gatekeeper itself — create superusers, run code. It's in CISA's KEV catalog and exploited in the wild. Here's the risk, and how BreachRisk finds and safely confirms exposed OAM.

April 30, 2025ThreatsAttack surface

CVE-2021-22986: F5 BIG-IP iControl REST unauthenticated remote code execution

A server-side request forgery in BIG-IP's iControl REST interface lets an unauthenticated attacker run commands on the appliance. It scores 9.8, it's in CISA KEV, and public exploits followed disclosure within days. Here's what to do, and how BreachRisk finds exposed BIG-IPs.

April 30, 2025ThreatsAttack surface

CVE-2020-5902: F5 BIG-IP TMUI unauthenticated remote code execution

A path-traversal flaw in the BIG-IP configuration interface (TMUI) lets an unauthenticated attacker run commands on the appliance. It scored 9.8, it's in CISA KEV, and it was mass-exploited within days. Here's what to do, and how BreachRisk finds exposed BIG-IPs.

April 30, 2025ThreatsAttack surface

CVE-2020-14882: Oracle WebLogic Console unauthenticated RCE, trivially exploited

A flaw in the Oracle WebLogic administration console lets an unauthenticated attacker run code with a single crafted request — weaponized within a week of the patch and swept up by botnets. It's in CISA's KEV catalog. Here's the risk, and how BreachRisk finds and safely confirms exposed WebLogic.

April 30, 2025ThreatsAttack surface

CVE-2019-2729: Oracle WebLogic unauthenticated deserialization RCE (a 2725 bypass)

A deserialization flaw in Oracle WebLogic's Web Services lets an unauthenticated attacker run code and take over the server — it emerged as a bypass of the CVE-2019-2725 patch and was exploited as a zero-day. Here's the risk, and how BreachRisk finds and safely confirms exposed WebLogic.

April 30, 2025ThreatsAttack surface

CVE-2019-2725: Oracle WebLogic unauthenticated deserialization RCE, widely exploited

A deserialization flaw in Oracle WebLogic's Web Services lets an unauthenticated attacker run code and take over the server — one of the most heavily exploited WebLogic bugs, used by cryptominers and ransomware. It's in CISA's KEV catalog. Here's the risk, and how BreachRisk finds and safely confirms exposed WebLogic.

April 29, 2025ThreatsAttack surface

CVE-2024-38812: VMware vCenter Server unauthenticated RCE, in CISA KEV

A heap-overflow flaw in vCenter Server's DCERPC implementation lets a network attacker run code on the appliance that manages your entire virtual estate. It's a 9.8 and it's in CISA's KEV catalog. Here's what to do, and how BreachRisk finds exposed vCenter.

April 29, 2025ThreatsAttack surface

CVE-2023-34048: VMware vCenter Server out-of-bounds write RCE, actively exploited

An out-of-bounds write in vCenter Server's DCERPC implementation gives an unauthenticated network attacker code execution on your virtualization control plane — used in real-world espionage intrusions and listed in CISA KEV. Here's what to do, and how BreachRisk finds exposed vCenter.

April 29, 2025ThreatsAttack surface

CVE-2022-47966: Zoho ManageEngine SAML unauthenticated RCE, actively exploited

An unsafe third-party XML library gives dozens of ManageEngine products an unauthenticated remote code execution flaw when SAML single sign-on is (or ever was) configured — exploited in the wild and in CISA KEV. Here's what to do, and how BreachRisk finds exposed ManageEngine.

April 29, 2025ThreatsAttack surface

CVE-2022-35405: Zoho ManageEngine Password Manager Pro / PAM360 unauthenticated RCE, actively exploited

A Java deserialization flaw in ManageEngine Password Manager Pro and PAM360 allows unauthenticated remote code execution on a server that holds privileged credentials — exploited in the wild and in CISA KEV. Here's what to do, and how BreachRisk finds and safely confirms exposed instances.

April 29, 2025ThreatsAttack surface

CVE-2021-40539: Zoho ManageEngine ADSelfService Plus auth bypass to RCE, actively exploited

A REST API authentication bypass in ManageEngine ADSelfService Plus leads to unauthenticated remote code execution — exploited by APT actors and in CISA KEV. Here's what to do, and how BreachRisk finds and safely confirms exposed ADSelfService Plus.

April 29, 2025ThreatsAttack surface

CVE-2021-21974: VMware ESXi OpenSLP heap overflow, mass-exploited by ESXiArgs

A heap-overflow flaw in the OpenSLP service on VMware ESXi lets an attacker on the same network run code on the hypervisor — the bug behind the ESXiArgs ransomware wave. Here's what to do, and how BreachRisk finds exposed ESXi hosts.

April 29, 2025ThreatsAttack surface

CVE-2021-21972: VMware vCenter unauthenticated RCE via vSphere Client plugin

A flaw in a default vCenter Server plugin lets an unauthenticated attacker with access to port 443 run commands on the host. It was mass-exploited and is in CISA's KEV catalog. Here's what to do, and how BreachRisk finds and safely confirms exposed servers.

April 28, 2025ThreatsAttack surface

CVE-2024-28987: SolarWinds Web Help Desk hardcoded credentials, actively exploited

SolarWinds Web Help Desk shipped with a hardcoded credential that lets an unauthenticated attacker read and modify help-desk data. It's in CISA's KEV catalog. Here's what to do, and how BreachRisk finds and safely confirms exposed instances.

April 28, 2025ThreatsAttack surface

CVE-2021-22005: VMware vCenter arbitrary file upload to RCE, exploited in the wild

A file-upload flaw in vCenter's Analytics service lets an attacker with access to port 443 execute code on the host — regardless of configuration. It was exploited in the wild and is in CISA's KEV catalog. Here's what to do, and how BreachRisk finds exposed servers.

April 28, 2025ThreatsAttack surface

CVE-2021-21985: VMware vCenter unauthenticated RCE via vSAN Health plugin

A flaw in vCenter's vSAN Health Check plugin — enabled by default even without vSAN — lets an attacker with access to port 443 run commands on the host. It's mass-exploited and in CISA's KEV catalog. Here's what to do, and how BreachRisk finds and safely confirms exposed servers.

April 25, 2025ThreatsAttack surface

CVE-2021-35211: SolarWinds Serv-U remote code execution, exploited in the wild

A memory flaw in SolarWinds Serv-U lets a remote attacker run code on the host with high privileges, and it was exploited as a targeted zero-day. It's in CISA's KEV catalog. Here's what to do, and how BreachRisk finds exposed servers.

April 24, 2025ThreatsAttack surface

CVE-2021-22900: Ivanti Connect Secure File Upload Vulnerability Exploitation (CVE-2021-22900)

A vulnerability allowed multiple unrestricted uploads in Pulse Connect Secure before 9.1R11.4 that could lead to an authenticated administrator to perform a file write via a maliciously crafted archive upload in the admi…

April 24, 2025ThreatsAttack surface

CVE-2025-42599: Qualitia Active! Mail unauthenticated buffer-overflow RCE, exploited in the wild

A stack buffer overflow in the Active! Mail webmail server lets an unauthenticated attacker run code or crash the service — a 9.8, exploited in the wild, and in CISA's KEV catalog. Here's what to do, and how BreachRisk finds exposed servers.

April 24, 2025ThreatsAttack surface

CVE-2024-22024: Ivanti Connect Secure XXE exposing restricted resources without authentication

An XML External Entity flaw in the SAML component of Ivanti Connect Secure lets an unauthenticated attacker reach restricted resources. It surfaced during the intense early-2024 targeting of Ivanti appliances and has a public proof-of-concept. Here's what to do, and how BreachRisk finds exposed gateways.

April 24, 2025ThreatsAttack surface

CVE-2022-20829: Cisco ASA/ASDM unsigned image code execution

A packaging-and-validation flaw lets an administrator upload a malicious ASDM image to a Cisco ASA that later runs code on management users' machines. It requires admin privileges on the device, which caps the risk. Here's the honest severity, and how BreachRisk finds exposed ASDM.

April 24, 2025ThreatsAttack surface

CVE-2021-22899: Pulse/Ivanti Connect Secure command injection, authenticated RCE

A command-injection flaw in Pulse Connect Secure (now Ivanti Connect Secure) lets an authenticated attacker run code on the VPN appliance via the Windows Resource Profiles feature. It's older and needs a login, but it's in CISA's KEV catalog. Here's the read, and how BreachRisk finds exposed appliances.

April 24, 2025ThreatsAttack surface

CVE-2021-22894: Pulse/Ivanti Connect Secure buffer overflow, authenticated RCE as root

A buffer overflow in Pulse Connect Secure (now Ivanti Connect Secure) lets an authenticated attacker run code as root on the VPN appliance. It's older and requires a login, but it's in CISA's KEV catalog. Here's the honest read, and how BreachRisk finds exposed appliances.

April 24, 2025ThreatsAttack surface

CVE-2021-22893: Ivanti (Pulse) Connect Secure authentication bypass, exploited by nation-state actors

A flaw in Pulse Connect Secure (now Ivanti) let unauthenticated attackers run code on the VPN gateway and slip past authentication — exploited as a zero-day by suspected nation-state actors. It's a perfect 10.0 and in CISA KEV. Here's what to do, and how BreachRisk finds exposed gateways.

April 24, 2025ThreatsAttack surface

CVE-2019-11510: Pulse/Ivanti Connect Secure arbitrary file read, unauthenticated and mass-exploited

A path-traversal flaw in Pulse Connect Secure (now Ivanti Connect Secure) lets an unauthenticated attacker read any file on the appliance — including credentials and session data. It was mass-exploited and tied to ransomware. Here's what to do, and how BreachRisk finds exposed appliances.

April 23, 2025ThreatsAttack surface

CVE-2021-30118: Kaseya VSA File Upload Vulnerability Exploitation (CVE-2021-30118)

An attacker can upload files with the privilege of the Web Server process for Kaseya VSA Unified Remote Monitoring & Management (RMM) 9.5.4.2149 and subsequently use these files to execute asp commands The api /SystemTab…

April 23, 2025ThreatsAttack surface

CVE-2021-30119: Kaseya VSA Cross-site Scripting Vulnerability Exploitation (CVE-2021-30119)

Affected Kaseya VSA servers are vulnerable to an authenticated reflective XSS in the HelpDeskTab/rcResults.asp endpoint. The parameter result of /HelpDeskTab/rcResults.asp is insecurely returned in the requested web page…

April 23, 2025ThreatsAttack surface

CVE-2021-30201: Kaseya VSA XML External Entity Reference ('XXE') Vulnerability Exploitation (CVE-2021-30201)

The API endpoint /vsaWS/KaseyaWS.asmx can be used to submit XML to the system. When this XML is processed (external) entities are insecurely processed and fetched by the system and returned to the attacker. Using this vu…

April 23, 2025ThreatsAttack surface

CVE-2021-30117: Kaseya VSA SQL Injection Vulnerability Exploitation (CVE-2021-30117)

The API call /InstallTab/exportFldr.asp is vulnerable to a semi-authenticated boolean-based blind SQL injection in the parameter fldrId. A valid session id is required for exploitation.

April 23, 2025ThreatsAttack surface

CVE-2021-30121: Kaseya VSA LFI Vulnerability Exploitation (CVE-2021-30121)

Semi-authenticated local file inclusion The contents of arbitrary files can be returned by the webserver Example request: `https://x.x.x.x/KLC/js/Kaseya.SB.JS/js.aspx?path=C:\Kaseya\WebPages\dl.asp` A valid sessionId is …

April 23, 2025ThreatsAttack surface

CVE-2021-301120: Kaseya 2FA Bypass Vulnerability Exploitation (CVE-2021-30120)

Kaseya VSA before 9.5.7 allows attackers to bypass the 2FA requirement. During the login process, after the user authenticates with username and password, the server sends a response to the client with the booleans MFARe…

April 23, 2025ThreatsAttack surface

CVE-2023-23752: Joomla! Information Disclosure Vulnerability Exploitation (CVE-2023-23752)

An issue was discovered in Joomla! 4.0.0 through 4.2.7. An improper access check allows unauthorized access to webservice endpoints.

April 23, 2025ThreatsAttack surface

CVE-2024-23917: JetBrains TeamCity authentication bypass leading to RCE

An authentication bypass in JetBrains TeamCity lets an unauthenticated attacker reach remote code execution on the CI/CD server. A fix is out in 2023.11.3. Here's the risk, and how BreachRisk finds exposed servers.

April 23, 2025ThreatsAttack surface

CVE-2023-6549: Citrix NetScaler unauthenticated denial of service and memory over-read

A memory-buffer flaw in NetScaler ADC and Gateway lets an unauthenticated attacker crash the appliance and read out-of-bounds memory when it's configured as a Gateway or AAA server. It's in CISA's KEV catalog. Here's the risk, and how BreachRisk finds exposed NetScalers.

April 23, 2025ThreatsAttack surface

CVE-2023-6548: Citrix NetScaler authenticated code injection via the management interface

A code-injection flaw in NetScaler ADC and Gateway that needs low-privilege access to the management interface. It's in CISA's KEV catalog, but the preconditions are real — and they're the reason the management plane should never face the internet. Here's the honest read, and how BreachRisk finds exposed NetScalers.

April 23, 2025ThreatsAttack surface

CVE-2023-4966 (CitrixBleed): NetScaler session-token leak that bypasses MFA

"CitrixBleed" leaks memory from NetScaler ADC/Gateway — including valid session tokens an attacker can replay to hijack sessions and skip MFA entirely. NVD calls it a 7.5; in the real world it was ransomware's front door. Here's why, and how BreachRisk finds exposed appliances.

April 23, 2025ThreatsAttack surface

CVE-2023-3519: Citrix NetScaler unauthenticated remote code execution

An unauthenticated code-injection flaw in NetScaler ADC and Gateway lets an attacker run code on the appliance with no credentials — exploited as a zero-day and tied to web-shell campaigns. Here's what to do, and how BreachRisk finds exposed NetScalers.

April 23, 2025ThreatsAttack surface

CVE-2022-27593: QNAP Photo Station externally controlled reference, exploited by DeadBolt ransomware

An externally controlled reference flaw in QNAP's Photo Station let attackers modify system files on internet-facing NAS devices — the vector behind a DeadBolt ransomware campaign. It's in CISA KEV. Here's what to do, and how BreachRisk finds exposed NAS.

April 23, 2025ThreatsAttack surface

CVE-2021-30116: Kaseya VSA Credential Disclosure Vulnerability Exploitation (CVE-2021-30116)

Kaseya VSA before 9.5.7 allows credential disclosure, as exploited in the wild in July 2021. By default Kaseya VSA on premise offers a download page where the clients for the installation can be downloaded. The default U…

April 23, 2025ThreatsAttack surface

CVE-2020-36195: QNAP NAS SQL injection in Multimedia Console / Media Streaming

An unauthenticated SQL injection in QNAP's Multimedia Console and Media Streaming add-on can expose application data on internet-facing NAS devices — patched just before the Qlocker ransomware wave. Here's what to do, and how BreachRisk finds exposed NAS.

April 23, 2025ThreatsAttack surface

CVE-2019-19781: Citrix ADC/Gateway path traversal leading to unauthenticated code execution

A directory-traversal flaw in Citrix ADC and Gateway ("Shitrix") lets an unauthenticated attacker reach restricted paths and run code on the appliance. A 9.8, in CISA KEV, tied to ransomware. Here's what to do, and how BreachRisk finds exposed appliances.

March 29, 2025ThreatsAttack surface

CVE-2017-12637: SAP NetWeaver AS Java directory traversal, unauthenticated file read

A directory-traversal flaw in SAP NetWeaver AS Java lets an unauthenticated attacker read arbitrary files from the server. It's in CISA's KEV catalog and has been exploited since 2017. Here's what to do, and how BreachRisk finds and safely verifies exposed NetWeaver.

March 23, 2025ThreatsAttack surface

Exposed WordPress admin logins and password spraying

Every WordPress site ships with a well-known admin login, which makes it a favorite target for password spraying. Weak or reused credentials turn that exposure into full control of the site. Here's the risk, and how BreachRisk safely tests whether the login holds.

March 23, 2025ThreatsAttack surface

Exposed web logins and password spraying

Any web application with a login on the public internet is a standing target for password spraying, and one weak or reused credential turns that exposure into access. Here's the risk — and how BreachRisk safely tests whether those logins hold.

March 23, 2025ThreatsAttack surface

Exposed WatchGuard VPN logins and password spraying

A WatchGuard VPN portal on the public internet is a standing target for password spraying, and one weak or reused credential turns that exposure into a direct foothold on your internal network. Here's the risk — and how BreachRisk safely tests whether those logins hold.

March 23, 2025ThreatsAttack surface

Exposed UniFi management logins and password spraying

A UniFi management portal on the public internet is a standing target for password spraying, and weak or reused credentials turn that exposure into control of your network gear. Here's the risk, and how BreachRisk safely tests whether those logins hold.

March 23, 2025ThreatsAttack surface

Exposed Telnet on the public internet

Telnet sends everything — including passwords — in cleartext, and an internet-facing Telnet service is both a credential-attack target and a live eavesdropping risk. Here's why it should be retired, and how BreachRisk finds it.

March 23, 2025ThreatsAttack surface

Exposed SSH and password-based brute forcing

An internet-facing SSH service that accepts password authentication is a standing target for brute-force and credential attacks. The fix is largely a configuration choice. Here's the risk, and how BreachRisk safely tests whether those credentials hold.

March 23, 2025ThreatsAttack surface

Exposed SonicWall Virtual Office logins and password spraying

A SonicWall Virtual Office portal on the public internet is a standing target for password spraying, and weak or reused credentials turn that exposure into VPN access to your network. Here's the risk, and how BreachRisk safely tests whether those logins hold.

March 23, 2025ThreatsAttack surface

Exposed Remote Desktop (RDP) on the public internet

An RDP service reachable from the public internet is a standing target for brute-force and password-spraying attacks — and one of the most common ways ransomware gets in. Here's the risk, and how BreachRisk finds exposed RDP.

March 23, 2025ThreatsAttack surface

PostgreSQL exposed to the internet

A PostgreSQL database reachable directly from the internet is a target it should never have been — open to credential brute-forcing against default and weak logins. Here's the risk, and how BreachRisk safely tests whether it holds.

March 23, 2025ThreatsAttack surface

Exposed Palo Alto management interface and password spraying

A Palo Alto firewall management interface on the public internet is a login that controls the firewall itself, and weak or reused credentials hand that control to an attacker. Here's the risk, and how BreachRisk safely tests whether it holds.

March 23, 2025ThreatsAttack surface

Exposed Palo Alto GlobalProtect VPN logins and password spraying

A Palo Alto GlobalProtect VPN portal is a door into the internal network, and weak or reused credentials open it. Here's the risk, and how BreachRisk safely tests whether that login holds.

March 23, 2025ThreatsAttack surface

MySQL exposed to the internet

A MySQL or MariaDB database reachable directly from the internet is a target it should never have been — open to credential brute-forcing against default and weak logins. Here's the risk, and how BreachRisk safely tests whether it holds.

March 23, 2025ThreatsAttack surface

Microsoft SQL Server exposed to the internet

A Microsoft SQL Server database reachable directly from the internet is a target it should never have been — open to credential brute-forcing against default and weak logins. Here's the risk, and how BreachRisk safely tests whether it holds.

March 23, 2025ThreatsAttack surface

Microsoft 365 password spraying against exposed logins

Applications that authenticate against Microsoft 365 inherit one of the most heavily sprayed login surfaces on the internet. Weak or reused credentials without MFA turn that into cloud account access. Here's the risk, and how BreachRisk safely tests whether it holds.

March 23, 2025ThreatsAttack surface

CVE-2021-26855: Microsoft Exchange ProxyLogon Vulnerability (CVE-2021-26855) Exploitation

Attempt to gain access to emails, sensitive files and internal network using a combination of Microsoft Exchange vulnerabilities.

March 23, 2025ThreatsAttack surface

Exposed Outlook on the web (OWA) and password spraying

An internet-facing Outlook Web Access / Exchange login is a well-known target for password spraying, and one weak credential opens a mailbox full of sensitive data. Here's the risk, and how BreachRisk safely tests whether that login holds.

March 23, 2025ThreatsAttack surface

Exposed LiquidFiles logins and password spraying

A LiquidFiles secure-file-transfer login on the public internet is a standing target for password spraying, and one weak or reused credential can hand an attacker the files it moves. Here's the risk, and how BreachRisk safely tests whether those logins hold.

March 23, 2025ThreatsAttack surface

Exposed Ivanti Connect Secure VPN logins and password spraying

An Ivanti Connect Secure (Pulse Secure) VPN login is a door straight into the internal network, and weak or reused credentials open it. Here's the risk, and how BreachRisk safely tests whether that login holds.

March 23, 2025ThreatsAttack surface

Exposed Ivanti Connect Secure admin portals and password spraying

The administrator portal of an Ivanti Connect Secure (Pulse Secure) VPN is a high-value login on the edge of your network. Weak or reused credentials turn that exposure into administrative control of the gateway. Here's the risk, and how BreachRisk safely tests whether it holds.

March 23, 2025ThreatsAttack surface

HTTP Basic Authentication exposed to the internet

A web resource protected only by HTTP Basic Authentication is a simple username-and-password prompt facing the internet — easy to spray, and only as strong as the password behind it. Here's the risk, and how BreachRisk safely tests whether it holds.

March 23, 2025ThreatsAttack surface

Exposed Gigapod file-storage logins and password spraying

A Gigapod file-storage login on the public internet is a standing target for password spraying, and weak or reused credentials turn that exposure into access to stored and shared files. Here's the risk — and how BreachRisk safely tests whether those logins hold.

March 23, 2025ThreatsAttack surface

FTP brute force against internet-facing file servers

An internet-facing FTP service is a standing target for credential guessing, and default, weak, or reused passwords turn that exposure into access. Here's the risk, and how BreachRisk safely tests whether those logins hold.

March 23, 2025ThreatsAttack surface

Anonymous FTP access on internet-facing file servers

An internet-facing FTP server that accepts anonymous logins hands unauthenticated strangers a foothold in your files — and sometimes a place to upload their own. No CVE, just a setting. Here's the risk, and how BreachRisk verifies it safely.

March 23, 2025ThreatsAttack surface

Fortinet Management Interface Password Spraying

Attempt authentication to Fortinet Management Interface using exposed or weak credentials.

March 23, 2025ThreatsAttack surface

Exposed Fortinet SSL VPN logins and password spraying

A Fortinet SSL VPN portal on the public internet is a standing target for password spraying, and one weak or reused credential turns that exposure into a foothold on your network. Here's the risk — and how BreachRisk safely tests whether those logins hold.

March 23, 2025ThreatsAttack surface

Exposed Fortinet FortiManager logins and password spraying

A Fortinet FortiManager login on the public internet is a standing target for password spraying, and one weak or reused credential can hand over central control of every firewall it manages. Here's the risk — and how BreachRisk safely tests whether those logins hold.

March 23, 2025ThreatsAttack surface

Exposed FortiGate logins and password spraying

A FortiGate login on the public internet is a standing target for password spraying, and one weak or reused credential turns that exposure into access through your firewall. Here's the risk — and how BreachRisk safely tests whether those logins hold.

March 23, 2025ThreatsAttack surface

Exposed FortiGate management logins and password spraying

A FortiGate management interface on the public internet is a standing target for password spraying, and one weak or reused credential can hand over administrative control of your firewall. Here's the risk — and how BreachRisk safely tests whether those logins hold.

March 23, 2025ThreatsAttack surface

Exposed FortiClient EMS logins and password spraying

A FortiClient Endpoint Management Server login on the public internet is a standing target for password spraying, and one weak or reused credential can hand over the console that manages your endpoint agents. Here's the risk — and how BreachRisk safely tests whether those logins hold.

March 23, 2025ThreatsAttack surface

Exposed Fortinet FortiAnalyzer logins and password spraying

A Fortinet FortiAnalyzer login on the public internet is a standing target for password spraying, and one weak or reused credential can expose the logs and analytics from across your Fortinet fabric. Here's the risk — and how BreachRisk safely tests whether those logins hold.

March 23, 2025ThreatsApplication security

Exposed Django admin logins and password spraying

A Django administrator portal on the public internet is a standing target for password spraying, and weak or reused credentials turn that exposure into privileged control of the application. Here's the risk — and how BreachRisk safely tests whether those logins hold.

March 23, 2025ThreatsAttack surface

CVE-2025-24813: Apache Tomcat path-equivalence flaw leading to RCE, actively exploited

A path-equivalence flaw in Apache Tomcat can expose sensitive files and, on a write-enabled default servlet, reach remote code execution via unsafe deserialization. It's in CISA's KEV catalog. Here's what to do, and how BreachRisk finds affected Tomcat.

March 23, 2025ThreatsAttack surface

CVE-2025-24472: Fortinet FortiOS authentication bypass via CSF proxy requests, exploited

A second FortiOS/FortiProxy authentication bypass — this one via crafted Security Fabric proxy requests — that can grant super-admin. It's in CISA KEV and was chained with CVE-2024-55591 in ransomware activity. Here's what to do, and how BreachRisk finds exposed FortiGates.

March 23, 2025ThreatsAttack surface

CVE-2025-22457: Ivanti Connect Secure stack buffer overflow, unauthenticated RCE, actively exploited

A stack-based buffer overflow in Ivanti Connect Secure lets a remote, unauthenticated attacker run code on the appliance — and it's been exploited in the wild. Here's what to do, and how BreachRisk finds exposed appliances.

March 23, 2025ThreatsAttack surface

CVE-2025-0282: Ivanti Connect Secure unauthenticated RCE, exploited as a zero-day

A stack-based buffer overflow in Ivanti Connect Secure lets an unauthenticated attacker run code on the VPN — and it was exploited as a zero-day before the fix shipped. Here's what to do, and how BreachRisk surfaces exposed appliances.

March 23, 2025ThreatsAttack surface

CVE-2025-0111: Palo Alto PAN-OS authenticated file read, chained to root

An authenticated file-read flaw in PAN-OS lets a low-privileged user read files on the firewall — modest alone, but it's being chained with an auth bypass and a privilege-escalation bug to reach root. It's in CISA KEV. Here's what to do, and how BreachRisk finds exposed interfaces.

March 23, 2025ThreatsAttack surface

CVE-2025-0108: Palo Alto PAN-OS management-interface authentication bypass, actively exploited

A path-confusion flaw between Nginx and Apache lets an unauthenticated attacker bypass authentication on the PAN-OS management interface — and it's being chained to root. It's in CISA KEV. Here's what to do, and how BreachRisk finds exposed interfaces.

March 23, 2025ThreatsAttack surface

CVE-2024-9474: Palo Alto PAN-OS privilege escalation to root, actively exploited

A PAN-OS administrator can escalate to root command execution on the firewall — and attackers chained it with an unauthenticated auth bypass to take over exposed devices. It's in CISA KEV. Here's what to do, and how BreachRisk finds exposed interfaces.

March 23, 2025ThreatsAttack surface

CVE-2024-6387 (regreSSHion): OpenSSH pre-auth RCE that's real but hard to exploit

regreSSHion is an unauthenticated remote code execution flaw in OpenSSH's server — serious on paper, but slow and unreliable to exploit in practice, and not in CISA's KEV catalog. Here's the honest severity, and how BreachRisk finds affected SSH.

March 23, 2025ThreatsAttack surface

CVE-2024-55591: Fortinet FortiOS authentication bypass to super-admin, actively exploited

An authentication-bypass flaw in FortiOS and FortiProxy lets a remote attacker reach super-admin via crafted Node.js websocket requests. It's in CISA KEV and tied to ransomware activity. Here's what to do, and how BreachRisk finds exposed FortiGates.

March 23, 2025ThreatsAttack surface

CVE-2024-4040: CrushFTP server-side template injection, unauthenticated and exploited

A server-side template injection flaw in CrushFTP lets an unauthenticated attacker read files outside the sandbox, bypass authentication, and reach code execution. It was a zero-day and is in CISA's KEV catalog. Here's what to do, and how BreachRisk finds exposed CrushFTP servers.

March 23, 2025ThreatsAttack surface

CVE-2024-3400: Palo Alto PAN-OS GlobalProtect unauthenticated RCE, root-level

A command-injection flaw in PAN-OS GlobalProtect lets an unauthenticated attacker run commands as root on the firewall — a perfect 10.0, exploited in the wild before the fix. Here's what to do, and how BreachRisk finds exposed firewalls.

March 23, 2025ThreatsAttack surface

CVE-2024-3393: Palo Alto PAN-OS DNS Security denial-of-service, actively exploited

A malicious DNS packet can reboot a PAN-OS firewall, and repeated attempts push it into maintenance mode — an outage of your perimeter. It's in CISA KEV and exploited in the wild. Here's what to do, and how BreachRisk finds exposed devices.

March 23, 2025ThreatsAttack surface

CVE-2024-28995: SolarWinds Serv-U directory traversal, actively exploited

A path-traversal flaw in SolarWinds Serv-U lets an unauthenticated attacker read files off the host, and it was exploited within days of disclosure. It's in CISA's KEV catalog. Here's what to do, and how BreachRisk finds and safely confirms exposed servers.

March 23, 2025ThreatsAttack surface

CVE-2024-24919: Check Point Security Gateway information disclosure, exploited in the wild

An arbitrary-file-read flaw in Check Point Security Gateways with remote-access VPN enabled lets an unauthenticated attacker pull sensitive files — including material that leads to full compromise. It was a zero-day and it's in CISA's KEV catalog. Here's what to do, and how BreachRisk finds exposed gateways.

March 23, 2025ThreatsAttack surface

CVE-2024-21893: Ivanti Connect Secure SSRF, chained for unauthenticated access and actively exploited

A server-side request forgery flaw in the SAML component of Ivanti Connect Secure lets an unauthenticated attacker reach restricted internal resources — and it was used to defeat Ivanti's own mitigation during the early-2024 exploitation wave. It's in CISA's KEV. Here's what to do, and how BreachRisk finds exposed appliances.

March 23, 2025ThreatsAttack surface

CVE-2024-21888: Ivanti Connect Secure privilege escalation to administrator

A privilege-escalation flaw in Ivanti Connect Secure and Policy Secure lets a lower-privileged user become an administrator. It's serious on a perimeter appliance, but unlike its siblings it isn't in CISA's KEV catalog. Here's the honest read, and how BreachRisk finds exposed appliances.

March 23, 2025ThreatsAttack surface

CVE-2024-21887: Ivanti Connect Secure command injection, actively exploited and chained to unauthenticated RCE

A command-injection flaw in Ivanti Connect Secure and Policy Secure lets crafted requests run arbitrary commands on the appliance — and paired with CVE-2023-46805 it became unauthenticated, in-the-wild remote code execution. Here's what to do, and how BreachRisk finds exposed appliances.

March 23, 2025ThreatsAttack surface

CVE-2024-21762: Fortinet FortiOS SSL VPN remote code execution, actively exploited

An unauthenticated remote-code-execution flaw in Fortinet's FortiOS SSL VPN has been exploited in the wild and sits in CISA's KEV catalog. Here's what matters — and how BreachRisk finds exposed FortiGate appliances before an attacker does.

March 23, 2025ThreatsApplication security

CVE-2024-21683: Atlassian Confluence authenticated remote code execution

A code-injection flaw in Confluence Data Center and Server lets an authenticated user with the right privilege run code on the server via the 'Add a new language' feature. Public exploit code exists. Here's what to do, and how BreachRisk finds exposed Confluence.

March 23, 2025ThreatsAttack surface

CVE-2024-0012: Palo Alto PAN-OS management-interface authentication bypass, actively exploited

An unauthenticated attacker who can reach a PAN-OS management web interface can bypass authentication and gain administrator access — then chain to root. It was exploited in the wild and is in CISA KEV. Here's what to do, and how BreachRisk finds exposed interfaces.

March 23, 2025ThreatsAttack surface

CVE-2023-46805: Ivanti Connect Secure authentication bypass, actively exploited and chained to RCE

An authentication bypass in Ivanti Connect Secure and Policy Secure lets a remote attacker skip access checks — and paired with CVE-2024-21887 it became unauthenticated remote code execution, exploited at scale as a zero-day. Here's what to do, and how BreachRisk finds exposed appliances.

March 23, 2025ThreatsApplication security

CVE-2023-22515: Atlassian Confluence broken access control, unauthenticated admin creation, actively exploited

A broken-access-control flaw in Confluence Data Center and Server lets a remote attacker create their own administrator account. It was a nation-state zero-day, it's a 9.8, and it's in CISA's KEV catalog. Here's what to do, and how BreachRisk finds exposed Confluence.

March 23, 2025ThreatsAttack surface

CVE-2023-20198: Cisco IOS XE Web UI unauthenticated admin account creation, mass-exploited

A flaw in the Cisco IOS XE Web UI lets an unauthenticated attacker create a privilege-15 account and take over the device. It's a perfect 10.0, it was mass-exploited across tens of thousands of routers and switches, and it's in CISA's KEV catalog. Here's what to do, and how BreachRisk finds exposed IOS XE.

March 23, 2025ThreatsAttack surface

CVE-2022-42475: Fortinet FortiOS SSL-VPN heap overflow, unauthenticated RCE exploited as a zero-day

A heap buffer overflow in the FortiOS SSL-VPN lets an unauthenticated attacker run code on the device. It scores 9.8, it's in CISA KEV, and it was exploited as a zero-day. Here's what to do, and how BreachRisk finds exposed FortiGates.

March 23, 2025ThreatsAttack surface

CVE-2022-40684: Fortinet FortiOS/FortiProxy authentication bypass, actively exploited

An authentication-bypass flaw in Fortinet FortiOS, FortiProxy, and FortiSwitchManager lets an unauthenticated attacker operate the administrative interface directly. It's in CISA KEV, tied to ransomware, and trivially reachable. Here's what to do, and how BreachRisk finds exposed appliances.

March 23, 2025ThreatsAttack surface

CVE-2022-39952: Fortinet FortiNAC unauthenticated remote code execution

A file-path control flaw in Fortinet FortiNAC lets an unauthenticated attacker write files and execute code on the appliance. It scores 9.8 and has a public exploit. Here's what to do, and how BreachRisk finds exposed FortiNAC.

March 23, 2025ThreatsApplication security

CVE-2022-22965 (Spring4Shell): Spring Framework RCE on Tomcat WAR deployments, actively exploited

Spring4Shell lets an unauthenticated attacker execute code against Spring MVC/WebFlux apps on JDK 9+ deployed as a WAR on Tomcat. It's in CISA's KEV catalog. Here's what to do, and how BreachRisk finds exposed Spring apps.

March 23, 2025ThreatsAttack surface

CVE-2022-0028: Palo Alto PAN-OS URL-filtering misconfiguration enabling reflected DoS

A URL-filtering policy misconfiguration can let an attacker abuse a PAN-OS firewall as a reflector for amplified TCP denial-of-service attacks against a target of their choosing. It's in CISA KEV. Here's the real picture, and how BreachRisk finds exposed devices.

March 23, 2025ThreatsAttack surface

CVE-2021-44529: Ivanti EPM Cloud Services Appliance code injection, unauthenticated RCE

A code-injection flaw in the Ivanti EPM Cloud Services Appliance lets an unauthenticated attacker run code on the internet-facing gateway. It's in CISA's KEV catalog and tied to ransomware. Here's what to do, and how BreachRisk finds exposed appliances.

March 23, 2025ThreatsAttack surface

CVE-2021-31207: Microsoft Exchange ProxyShell Vulnerability (CVE-2021-34473) Exploitation

Attempt to gain access to emails, sensitive files and internal network using a combination of Microsoft Exchange vulnerabilities.

March 23, 2025ThreatsAttack surface

CVE-2021-1585: Cisco ASDM Launcher code execution via man-in-the-middle

A signature-verification flaw in the Cisco ASDM Launcher lets a network attacker in a man-in-the-middle position run code on an administrator's machine. It targets the admin's client, not the appliance, and needs a privileged network position. Here's the honest severity, and how BreachRisk finds exposed ASDM.

March 23, 2025ThreatsAttack surface

CVE-2020-3452: Cisco ASA/FTD web-services path traversal, unauthenticated file read

A path-traversal flaw in the web services of Cisco ASA and Firepower Threat Defense lets an unauthenticated attacker read files from the appliance. It's read-only and bounded — but it's mass-scanned and in CISA's KEV catalog. Here's what to do, and how BreachRisk finds exposed devices.

March 23, 2025ThreatsAttack surface

CVE-2020-2021: Palo Alto PAN-OS SAML authentication bypass, in CISA KEV

When SAML is enabled and certificate validation is turned off, a PAN-OS device can be tricked into accepting a forged assertion — bypassing authentication. It scores a 10.0 but depends on a specific misconfiguration. Here's the real picture, and how BreachRisk finds exposed devices.

March 23, 2025ThreatsAttack surface

CVE-2020-14181: Atlassian Jira user enumeration, unauthenticated

A low-impact flaw in Jira Server and Data Center lets an unauthenticated visitor enumerate valid usernames via the ViewUserHover endpoint. Harmless alone, but it feeds password spraying. Here's the honest severity, and how BreachRisk finds exposed Jira.

March 23, 2025ThreatsAttack surface

CVE-2020-14179: Atlassian Jira information disclosure, unauthenticated field enumeration

A low-impact information-disclosure flaw in Jira Server and Data Center lets an unauthenticated visitor view custom field and SLA names. It's not a breach on its own, but it's useful reconnaissance. Here's the honest severity, and how BreachRisk finds exposed Jira.

March 23, 2025ThreatsApplication security

CVE-2019-3396: Atlassian Confluence Widget Connector template injection, unauthenticated RCE

A server-side template injection flaw in the Confluence Widget Connector macro lets an unauthenticated attacker read files and run code on the server. It's a 9.8, it's in CISA's KEV catalog, and it was used to deliver ransomware. Here's what to do, and how BreachRisk finds exposed Confluence.

March 23, 2025ThreatsAttack surface

CVE-2018-13379: Fortinet FortiOS SSL VPN pre-auth file read, still exploited years on

A path-traversal flaw in the FortiOS SSL VPN lets an unauthenticated attacker read system files — including session data with plaintext VPN credentials. It's in CISA KEV and still being exploited years after the fix. Here's what to do, and how BreachRisk finds exposed FortiGates.

March 23, 2025ThreatsAttack surface

CVE-2025-2825: CrushFTP Authentication Bypass Vulnerability Exploitation (CVE-2025-2825)

A server side template injection vulnerability in CrushFTP in all versions before 10.7.1 and 11.1.0 on all platforms allows unauthenticated remote attackers to read files from the filesystem outside of the VFS Sandbox, b…

March 23, 2025ThreatsAttack surface

CVE-2025-2825: CrushFTP Authentication Bypass Vulnerability Exploitation (CVE-2025-2825)

CrushFTP versions 10.0.0 through 10.8.3 and 11.0.0 through 11.3.0 are affected by a vulnerability that may result in unauthenticated access. Remote and unauthenticated HTTP requests to CrushFTP may allow attackers to gai…

March 23, 2025ThreatsAttack surface

Exposed Citrix VPN logins and password spraying

A Citrix VPN login on the public internet is a high-value target for password spraying, and one weak credential can hand an attacker a foothold inside your network. Here's the risk — and how BreachRisk safely tests whether those logins hold.

March 23, 2025ThreatsAttack surface

Exposed Cisco TelePresence logins and password spraying

A Cisco TelePresence login on the public internet is a standing target for password spraying, and one weak or reused credential can expose your conferencing systems and the meetings they carry. Here's the risk — and how BreachRisk safely tests whether those logins hold.

March 23, 2025ThreatsAttack surface

Exposed Cisco Systems logins and password spraying

A Cisco Systems login on the public internet is a standing target for password spraying, and one weak or reused credential turns that exposure into a foothold on your network gear. Here's the risk — and how BreachRisk safely tests whether those logins hold.

March 23, 2025ThreatsAttack surface

Exposed Cisco ServiceGrid logins and password spraying

A Cisco ServiceGrid login on the public internet is a standing target for password spraying, and one weak or reused credential can expose the service data and integrations it brokers. Here's the risk — and how BreachRisk safely tests whether those logins hold.

March 23, 2025ThreatsAttack surface

Exposed Cisco SD-WAN Manager logins and password spraying

A Cisco SD-WAN Manager login on the public internet is a standing target for password spraying, and one weak or reused credential can hand over the controller for your entire WAN fabric. Here's the risk — and how BreachRisk safely tests whether those logins hold.

March 23, 2025ThreatsAttack surface

Exposed Cisco Prime Infrastructure logins and password spraying

A Cisco Prime Infrastructure login on the public internet is a standing target for password spraying, and one weak or reused credential can hand over the platform that manages your network devices. Here's the risk — and how BreachRisk safely tests whether those logins hold.

March 23, 2025ThreatsAttack surface

Exposed Cisco Meraki management logins and password spraying

A Cisco Meraki management panel on the public internet is a standing target for password spraying, and one weak or reused credential turns that exposure into control of network devices. Here's the risk — and how BreachRisk safely tests whether those logins hold.

March 23, 2025ThreatsAttack surface

Exposed Cisco IOS XE web logins and password spraying

A Cisco IOS XE web interface on the public internet is a standing target for password spraying, and one weak or reused credential turns that exposure into access to the device that runs your network. Here's the risk — and how BreachRisk safely tests whether those logins hold.

March 23, 2025ThreatsAttack surface

Exposed Cisco ASA VPN logins and password spraying

A Cisco ASA VPN portal on the public internet is a standing target for password spraying, and one weak or reused credential turns that exposure into remote access to your network. Here's the risk — and how BreachRisk safely tests whether those logins hold.

March 23, 2025ThreatsAttack surface

Exposed Centricity PLL portal logins and password spraying

A Centricity permitting-and-licensing portal on the public internet is a standing target for password spraying, and weak or reused credentials turn that exposure into access to sensitive citizen and permit records. Here's the risk — and how BreachRisk safely tests whether those logins hold.

March 23, 2025ThreatsAttack surface

Exposed BOSSDesk help-desk logins and password spraying

A BOSSDesk help-desk login on the public internet is a standing target for password spraying, and weak or reused credentials turn that exposure into access to sensitive support data. Here's the risk — and how BreachRisk safely tests whether those logins hold.

March 23, 2025ThreatsAttack surface

Exposed Atlassian Jira logins and password spraying

A Jira login on the public internet is a standing target for password spraying, and weak or reused credentials turn that exposure into access to your projects, tickets, and the sensitive detail they hold. Here's the risk, and how BreachRisk safely tests whether that login holds.

March 12, 2025ThreatsApplication security

CVE-2025-24893: XWiki unauthenticated RCE via SolrSearch, actively exploited

A code-injection flaw in XWiki's SolrSearch lets any guest run code on the server with a single unauthenticated request. It's a 9.8, it's in CISA KEV, and EPSS is near the ceiling. Here's what to do, and how BreachRisk finds and safely confirms exposed XWiki.