
CVE-2025-34171
CasaOS expose multiple unauthenticated API endpoints that allow remote disclosure of sensitive configuration files and system debug information

CasaOS expose multiple unauthenticated API endpoints that allow remote disclosure of sensitive configuration files and system debug information

Vatilon-based IP cameras expose internal web directories without authentication, leading to information disclosure.

BeHat Configuration file leaking

Appspec YML and YAML leaks

This tool is used to find php info page

The WP Page Permalink Extension plugin (<= 1.5.4) allows authenticated users with insufficient privileges to trigger the AJAX action…

CVE-2025-54554 – Unauthenticated Access in tiaudit REST API leading to Sensitive Information Disclosure

CVE-2023-5142

IBM i Access Client Solution < 1.1.9.4 - Local server broken access control.

[Reserved for CVE-2022-30006]

CGI Print ENV leaking

WordPress Plugin Metform <= 2.1.3 - Improper Access Control Allowing Unauthenticated Sensitive Information Disclosure


Element55 Maketime Appliance stores passwords in cleartext within the application.

Samsung Printer SCX-6X55X Improper Access Control

Chevereto information disclosure <= 3.13.5 Core

Checks for exposed Redis servers