Findings
All discovered vulnerabilities across your projects
TOTAL FINDINGS
0
AFFECTED HOSTS
0
CREDENTIALS
0
SERVICES
0
All Findings
Domain Admin Compromise via Kerberoasting
Domain Compromise · CWE-916
/auth/kerberosRemote Code Execution — Spring Boot Actuator
Remote Code Execution · CWE-94
/actuator/envSQL Injection — User Authentication Endpoint
Injection · CWE-89
/api/auth/loginExposed JMX Service — Unauthenticated Access
Service Exploitation · CWE-306
/jmx-consoleLDAP Injection via Search Parameter
Injection · CWE-90
/api/directory/searchPrivilege Escalation — Misconfigured sudo Rules
Privilege Escalation · CWE-269
/etc/sudoersCross-Site Scripting (Stored) — Comment Field
Client-Side Attack · CWE-79
/api/commentsOutdated TLS 1.0 Enabled on HTTPS Endpoint
Configuration Weakness · CWE-326
/ssl/configMissing HTTP Security Headers (CSP, HSTS)
Configuration Weakness · CWE-693
/headersDefault Credentials on Admin Panel
Credential Weakness · CWE-798
/admin/login