picture
LeakIX is now available as a Metasploit module. Search, host lookups, subdomains, and leaks directly from msfconsole.
github.com/rapid7/metasploit-framew...
picture
LeakIX is now available as a Metasploit module. Search, host lookups, subdomains, and leaks directly from msfconsole.
github.com/rapid7/metasploit-framew...
picture
๐จ Plugin update: ZimbraPlugin (CVE-2025-68645).
Zimbra Collaboration Suite 10.0 and 10.1 affected by unauthenticated LFI vulnerability.
Results: leakix.net/search
picture
๐จ New plugin: SmarterMailPlugin (CVE-2025-52691).
SmarterMail versions prior to Build 9413 affected by critical remote code execution vulnerability via arbitrary file upload.
Results: leakix.net/search
picture
๐จ New plugin: MongoBleedPlugin (CVE-2025-14847).
MongoDB Memory Leak vulnerability detection.
Results: leakix.net/search
picture
๐จ New plugin: N8nPlugin (CVE-2025-68613, CVE-2025-65964, CVE-2025-62726).
n8n Workflow Automation multiple vulnerabilities detection.
Results: leakix.net/search
picture
๐จ New plugin: GeoserverXxePlugin (CVE-2025-58360).
GeoServer XXE vulnerability detection - XML External Entity injection in WMS GetMap operation, added to CISA KEV catalog.
Results: leakix.net/search
picture
๐จ Plugin update: React2ShellPlugin (CVE-2025-55182).
Backdoor detection added - 16k+ Next.js servers detected with in-memory webshells allowing remote code execution.
Results: leakix.net/search
picture
๐จ New plugin: React2ShellPlugin (CVE-2025-55182).
React Server Components RCE vulnerability detection - Next.js applications affected by critical remote code execution vulnerabilities.
Results: leakix.net/search
picture
๐จ New plugin: EzGED3Plugin (CVE-2025-51539).
EzGED3 pre-authentication arbitrary file read vulnerability detection - may lead to admin takeover.
Results: leakix.net/search
picture
๐จ New plugin: FreePBXPlugin (CVE-2025-57819).
FreePBX unauthenticated SQL injection vulnerability detection - may lead to RCE.
Results: leakix.net/search
picture
๐จ New plugin: TraccarPlugin (CVE-2025-61666).
Traccar local file inclusion vulnerability detection - may expose configuration files.
Results: leakix.net/search
picture
๐จ New plugin: KestrelPlugin (CVE-2025-55315).
Kestrel HTTP request smuggling vulnerability detection.
Results: leakix.net/search
picture
๐จ New plugin: XWikiPlugin (CVE-2025-24893, CVE-2025-32429, CVE-2025-52472, CVE-2025-55748).
XWiki multiple critical vulnerabilities detection - RCE, SQL/HQL injection, and path traversal.
Results: leakix.net/search
picture
๐จ New plugin: FlowiseVersionPlugin.
Flowise vulnerability detection - detects 15+ CVEs including RCE, file upload, and SSRF vulnerabilities.
Results: leakix.net/search
picture
๐จ New plugin: WazuhPlugin (CVE-2025-24016).
Wazuh default credentials and RCE vulnerability detection - RCE possible on multi-node configurations, versions 4.4.0 to 4.9.1 affected.
Results: leakix.net/search
picture
๐จ New plugin: ICTBroadcastRcePlugin (CVE-2025-2611).
ICTBroadcast unauthenticated RCE vulnerability detection.
Results: leakix.net/search
picture
๐จ New plugin: SpipRcePlugin (CVE-2024-8517).
SPIP BigUp plugin pre-authentication RCE vulnerability detection.
Results: leakix.net/search
picture
๐จ New plugin: ViciboxVersionPlugin (CVE-2024-8503, CVE-2024-8504).
VICIdial outdated version detection - unauthenticated SQL injection and authenticated RCE, versions <= 2.14-917a affected.
Results: leakix.net/search
picture
๐จ New plugin: NCentralPlugin (CVE-2025-9316, CVE-2025-11700).
N-able N-Central session bypass and XXE vulnerability detection - XXE allows reading critical files.
Results: leakix.net/search
picture
๐จ New plugin: MagentoXxePlugin (CVE-2024-34102, CosmicSting).
Magento XXE injection vulnerability detection - may expose sensitive files, RCE possible in some cases.
Results: leakix.net/search
picture
๐จ Plugin update: PaloAltoPlugin (CVE-2024-3400, CVE-2025-0133).
PaloAlto PAN-OS XSS vulnerability detection added - GlobalProtect portal affected.
Results: leakix.net/search
picture
๐จ New plugin: GeoserverRcePlugin (CVE-2024-36401).
GeoServer RCE vulnerability detection via GetPropertyValue in WFS requests.
Results: leakix.net/search
picture
๐จ New plugin: SwaggerUIPlugin.
Swagger API documentation public exposure detection - may expose API endpoints, parameters, and data structures.
Results: leakix.net/search
picture
๐จ New plugin: PrometheusPlugin.
Prometheus server public exposure detection - may expose metrics, configuration, and infrastructure information.
Results: leakix.net/search
picture
๐จ New plugin: GraphQLIntrospectionPlugin.
GraphQL introspection enabled detection - may expose sensitive schema information and database structures.
Results: leakix.net/search
picture
๐จ New plugin: WatchGuardFireboxPlugin (CVE-2025-59396).
WatchGuard Firebox default credentials allow administrative SSH access. CVE rejected by NVD: "Not a security vulnerability".
Results: leakix.net/search
picture
๐จ New plugin: GladinetPlugin (CVE-2025-11371, CVE-2025-30406, CVE-2025-12480).
Gladinet CentreStack/Triofox LFI, RCE, and auth bypass vulnerability detection.
Results: leakix.net/search
picture
๐จ New plugin: GLPIVersionPlugin.
GLPI vulnerability detection - detects 50+ CVEs including unauthenticated SQL injection, session hijacking, and account takeover.
Results: leakix.net/search
picture
๐จ New plugin: MonstaFtpVersionPlugin (CVE-2025-34299).
MonstaFTP RCE vulnerability detection - versions < 2.11.3 affected.
Results: leakix.net/search
picture
๐จ New plugin: SessionReaperPlugin (CVE-2025-54236) added.
Multiple Adobe Commerce / Magento instances exposed. Patch ASAP.
Details: slcyber.io/assetnote-security-resea...
Query: +plugin:SessionReaperPlugin