Security checks

Every scan runs real security checks drawn from years of penetration testing. Not checkbox compliance - the same methodology a researcher would use against your app.

How to fix these findings

Recently added

Last 24 hours

WordPress CVE-2026-94389 AcyMailing – An Ultimate Newsletter Plugin and Marketing Automation Solution for WordPress <= 11.0.5 - Unauthenticated Remote Code Execution
WordPress CVE-2026-32579 Kognetiks Chatbot <= 2.4.9 - Unauthenticated Arbitrary File Upload
WordPress CVE-2026-103065 Kirki – Freeform Page Builder, Website Builder & Customizer <= 6.3.1 - Unauthenticated Remote Code Execution
WordPress CVE-2026-96349 SiteSkite – Secure MCP & AI WebOps. Connect ChatGPT, Claude, or Any AI Agent via MCP <= 2.1.8 - Unauthenticated Remote Code Execution
WordPress CVE-2026-39770 Doctreat - Hospitals and Doctors Directory WordPress Listing Theme <= 1.7.0 - Unauthenticated Arbitrary File Upload
WordPress CVE-2026-97283 Advanced Post Manager <= 4.5.5 - Authenticated (Contributor+) PHP Object Injection
WordPress CVE-2026-32575 SUMO Affiliates Pro <= 11.7.0 - Unauthenticated Stored Cross-Site Scripting
WordPress CVE-2026-39778 Ansar Import – One Click Starter Sites – for WordPress Themes <= 2.1.2 - Unauthenticated Stored Cross-Site Scripting
WordPress CVE-2026-39766 ARforms <= 7.1.2 - Unauthenticated Stored Cross-Site Scripting
WordPress CVE-2026-42417 ARMember Premium – Membership Plugin, Content Restriction, Member Levels, User Profile & User signup <= 7.8 - Unauthenticated SQL Injection

Verified exploits

191

We don't just detect these vulnerabilities. We prove they're exploitable on your app with safe, non-destructive proof-of-concept payloads.

CVE-2026-86350
Deterministic critical

HTTP/2 Request Header Mix-Up (Request Smuggling)

Detects Apache Tomcat servers whose HTTP/2 connector mixes headers between requests on the same connection. The compression scheme HTTP/2 uses for headers keeps a shared table that both sides have to agree on for the whole connection. On these versions Tomcat checks each header for illegal characters from inside that shared decoder, and when it finds one it stops reading the rest of the request's headers but keeps the connection open. Everything after the rejected header is therefore never recorded, so the two sides no longer agree on the table, and every later request on that connection resolves indexed headers to the wrong values. We show that with two connections. On the first, a marker header is stored and then re-used by index on a second request, which answers. On the second connection that same second request goes unanswered, because one extra header with a trailing space was placed ahead of the marker. Upgrade Tomcat to 11.0.26, 10.1.60 or 9.0.122. Until you upgrade, turn HTTP/2 off on every connector.

Apache Tomcat

Added 7d ago

CVE-2025-48384
Deterministic critical

Submodule Carriage-Return Config Confusion (Clone RCE)

Detects services that clone attacker-influenced repositories with a git build older than the July 2025 fix, where a plain recursive clone runs attacker code. Git strips a trailing carriage return when it reads a config value but does not quote one when it writes it, so a submodule whose recorded path ends in a carriage return gets written into the submodule config and read back as a shorter, different path. A symlink committed at that shorter path redirects the submodule checkout, and because the redirect comes from config rather than the working tree, git writes through it without the usual symlink protections. Point it at the submodule hooks directory, track an executable post-checkout file in the submodule, and git runs that file to finish the very checkout that created it. We prove it by reading our own marker, a product only the target could compute, and the uid of the clone process out of the clone log. Repository importers, CI and build runners, mirrors and docs pipelines are the exposed surface. In the CISA known-exploited catalogue since August 2025. Upgrade git to 2.50.1, 2.49.1, 2.48.2, 2.47.3, 2.46.4, 2.45.4, 2.44.4 or 2.43.7.

Git CISA KEV

Added 8d ago

CVE-2026-92956
Deterministic critical

WebAssembly Streaming-Compile Sandbox Escape (RCE)

Detects vm2 sandboxes that an attacker can break out of through WebAssembly.compileStreaming or WebAssembly.instantiateStreaming, yielding code execution on the host. On Node.js 26 those two calls hand the sandbox a Promise whose prototype belongs to the host, so vm2's own then/catch overrides and its species hardening never run on it. Guest code plants its own Symbol.species on that Promise and calls finally(), which delivers the raw host-realm error straight into the sandbox; the error's Function constructor then compiles code in the host realm and yields the host process object. We prove it by running a shell command on the host and reading back a product only the target could have computed. No unsafe configuration is needed: a default new VM() with no host objects exposed is enough, so anyone who can submit JavaScript owns the machine. This is a bypass of the earlier WebAssembly JSPI fix. vm2 3.10.1 through 3.11.6 affected. Upgrade to vm2 3.11.7, or migrate off the deprecated vm2 to isolated-vm.

vm2

Added 10d ago

Authenticated Testing

Unauthenticated API access, exposed admin and debug endpoints, CSRF protection, and host header injection, tested with real credentials

Access Control Testing

Warden+

Tests whether JSON API endpoints discovered during authenticated crawling also return data without credentials

Example: API endpoint returns data without authentication

CSRF Protection

Warden+

Validates CSRF defenses on state-changing forms and endpoints

Example: CSRF token missing on password change form

Auth Endpoint Discovery

Warden+

Probes common admin, debug, API documentation, and monitoring endpoints and records which are accessible

Example: Server metrics readable by anyone

Host Header Injection

Warden+

Tests for host header manipulation that can poison password reset links and caches

Example: Host header injection in password reset emails

Application Security

Exposed files, secrets, technology fingerprinting, and active vulnerability probing

Exposed File Detection

Starter

Probes for accidentally exposed files like .env, .git directories, and database backups

Example: .env file publicly accessible with database credentials

Tech Stack Detection

Starter

Fingerprints frameworks, libraries, and server versions to identify known vulnerabilities

Example: Running Laravel 10.48 with 3 known CVEs

WordPress Plugin CVEs

Starter

Checks WordPress plugins and themes against known vulnerability databases

Example: Contact Form 7 plugin has known XSS vulnerability

Secret Detection

Starter

Finds API keys, tokens, and credentials exposed in JavaScript and HTML source code

Example: API key found in client-side JavaScript bundle

Information Leakage

Starter

Detects stack traces, debug pages, and verbose error messages that reveal internals

Example: Full stack trace exposed in 500 error response

CVE Verification

Starter

Actively proves whether known CVEs are exploitable on your app, not just present

Example: CVE-2024-1234 confirmed exploitable on this server

Technology Probes

Starter

Tests for technology-specific misconfigurations like debug modes and exposed admin panels

Example: Laravel debug mode enabled, exposing environment variables

JWT Security Audit

Starter

Analyzes JSON Web Token signing configuration and algorithm weaknesses

Example: JWT accepts 'none' algorithm, bypassing signature verification

Open Redirect Detection

Starter

Tests whether URL parameters can redirect users to malicious external domains

Example: Redirect parameter accepts arbitrary external URLs

Clickjacking

Starter

Finds framable pages with forms that change state, where an invisible overlay can make a visitor submit them

Example: Password change form can be framed from another origin

CDN JavaScript Library Vulnerabilities

Starter

Detects vulnerable JavaScript libraries loaded from CDN URLs with known CVEs

Example: jQuery 3.4.1 loaded from cdnjs has 6 known CVEs

Headers & Configuration

HTTP response headers, caching policies, content security, and cookie settings

Security Headers

Starter

Checks for missing or misconfigured HTTP security headers like X-Frame-Options and HSTS

Example: Missing Content-Security-Policy header

Content Security Policy

Starter

Deep analysis of CSP directives for bypasses and unsafe-inline usage

Example: CSP allows unsafe-inline scripts

Cache Configuration

Starter

Identifies caching misconfigurations that could leak sensitive data to shared caches

Example: Cache-Control missing on authenticated page

Content-Type Validation

Starter

Validates Content-Type headers and MIME sniffing protection

Example: Missing X-Content-Type-Options header

Cookie Security

Starter

Checks cookie security flags including Secure, HttpOnly, and SameSite attributes

Example: Session cookie missing HttpOnly flag

CDN & WAF Detection

Starter

Fingerprints CDN and WAF providers from response headers and behavior

Example: Cloudflare WAF detected with default ruleset

HTTP Methods

Starter

Probes for dangerous HTTP methods like PUT, DELETE, and TRACE that should be disabled

Example: TRACE method enabled, echoing request headers back to the caller (XST)

Well-Known Endpoints

Starter

Checks .well-known endpoints for security.txt and exposed configuration files

Example: Missing security.txt contact information

Network & DNS

Transport-level checks covering DNS, TLS, and email security configuration

DNS Records

Starter

Analyzes DNS configuration for dangling records, missing entries, and subdomain takeover risks

Example: Dangling CNAME pointing to unclaimed cloud service

DNSSEC Validation

Starter

Checks whether DNSSEC is configured and validates correctly

Example: Domain is not signed with DNSSEC

TLS Configuration

Starter

Validates SSL/TLS certificate chain, expiry dates, and cipher configuration

Example: TLS certificate expires in 12 days

Email Security

Starter

Checks SPF, DKIM, and DMARC records for protection against forged email

Example: Missing DMARC record allows forged email from your domain

CORS Configuration

Starter

Tests Cross-Origin Resource Sharing policy for overly permissive rules

Example: CORS allows any origin to read responses

Authenticated CORS

Starter

Repeats the CORS checks against endpoints that need a login, using real credentials

Example: Any origin can read a logged-in user's data

Redirect Analysis

Starter

Analyzes HTTP redirect chains for missing HTTPS upgrades and redirect loops

Example: HTTP to HTTPS redirect missing on main domain

See what attackers see

Start with a free 14-day Starter trial. Active probing that proves what's actually exploitable, not just a checklist.

Scan your app