TGViewer
Channel Public Channel
Netlas.io

Netlas.io

@netlas

Explore the latest in cybersecurity with Netlas.io. Stay ahead with updates on high-profile vulnerabilities, expert tutorials, essential safety tips, and the latest Netlas developments.
Subscribers
2.32K
Photos
434
Videos
3
Links
575

Showing posts older than #375 · Back to latest

Older Posts 20 shown
Post #373 583
CVE-2025-3083, -3084, -3085: Vulnerabilities in MongoDB, 6.5 - 8.1 rating❗️

Vulnerabilities in some versions of MongoDB allow attackers to perform DoS and gain unauthorized access using revoked certificates.

Search at Netlas.io:
👉 Link: https://nt.ls/aqCrV
👉 Dork: mongodb.build_info.version:[6.0.0 TO 6.0.20] OR mongodb.build_info.version:[5.0.0 TO 5.0.31] OR mongodb.build_info.version:[7.0.0 TO 7.0.16]

Vendor's advisory: https://jira.mongodb.org/browse/SERVER-95445
  • 🔥 5
  • 👾 2
Post #371 589
CVE-2025-30232: Use-after-free in Exim, "medium" rating❗️

A vulnerability in some versions of Exim potentially allows an attacker to perform Privilege Escalation, if he has command line access.

Search at Netlas.io:
👉 Link: https://nt.ls/mtDNc
👉 Dork: smtp.banner:"Exim 4.96" OR smtp.banner:"Exim 4.97" OR smtp.banner:"Exim 4.98" OR smtp.banner:"Exim 4.98.1"

Vendor's advisory: https://exim.org/static/doc/security/CVE-2025-30232.txt
  • 👾 4
  • 🔥 2
Post #370 565
CVE-2025-1974: Improper Isolation or Compartmentalization in Kubernetes Ingress Controller, 9.8 rating 🔥

In some cases, an unauthenticated attacker may be able to execute remote code in the context of the ingress-nginx controller.

Search at Netlas.io:
👉 Link: https://nt.ls/G6SC7
👉 Dork: certificate.issuer_dn:"Kubernetes Ingress Controller"

Vendor's advisory: https://github.com/kubernetes/kubernetes/issues/131009
  • 🔥 4
  • 👾 3
Post #367 513
🚧 Planned Maintenance 🚧
The application will be unavailable for a period of time❗️

We remind you that in an hour, at 08:00 UTC ⏰, planned server maintenance will begin. It is expected to take a couple of hours, and we will do our best to complete it as quickly as possible.

Please remember to save your work before this time.
  • 🕊 3
  • 🤝 2
  • 👨‍💻 1
Post #366 584
Netlas vs ZoomEye: A Comprehensive Analysis 🧮

The final article in our series of comparisons with competitors.

This time we looked at ZoomEye, honestly comparing it with Netlas on more than 10 key metrics.

👉 Read now: https://netlas.io/blog/netlas_vs_zoomeye/
netlas.io Netlas vs ZoomEye: Platforms Comparison - Netlas Blog Compare IoT search engines Netlas and Zoomeye, highlighting their features, strengths, and ideal use cases for security research.
  • 👾 6
  • 👍 5
Post #365 552
CVE-2025-2505: Path Traversal in Age Gate WordPress plugin, 9.8 rating 🔥

A vulnerability in a popular plugin allows attackers to include and execute arbitrary PHP files, potentially executing the code contained within.

Search at Netlas.io:
👉 Link: https://nt.ls/3gfAq
👉 Dork: http.body:"plugins/age-gate"

Read more: https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/age-gate/age-gate-353-unauthenticated-local-php-file-inclusion-via-lang
  • 🔥 5
  • 👾 2
  • 👍 1
Post #363 494
🚧 Planned Maintenance 🚧
The application will be unavailable for a period of time❗️

The maintenance is scheduled to start on March 23, 2025, at 08:00 UTC ⏰. It is expected to take a couple of hours, and we will do our best to complete it as quickly as possible.

Please remember to save your work before this time.
  • 💊 3
  • 👨‍💻 1
Post #362 620
CVE-2024-13918, -13919: XSS in Laravel Framework, 8.0 rating❗️

The vulnerabilities allow an attacker to execute code in the victim's browser via Reflected XSS if the victim clicks on a decoy link.

More then 770k instances at Netlas.io:
👉 Link: https://nt.ls/95OAY
👉 Dork: http.headers.set_cookie:"laravel_session="

Read more: https://github.com/sbaresearch/advisories/tree/public/2024/SBA-ADV-20241209-01_Laravel_Reflected_XSS_via_Request_Parameter_in_Debug-Mode_Error_Page
  • ❤ 5
  • 🔥 3
  • 👾 3
Post #361 617
Netlas Plugins Update ⚡️

We've updated our Google Chrome and Mozilla Firefox plugins, fixing some bugs and improving stability. If you use them, we recommend updating to the latest version!

👉 Netlas for Chrome: https://chromewebstore.google.com/detail/netlasio/pncoieihjcmpooceknjajojehmhdedii
👉 Netlas for Firefox: https://addons.mozilla.org/en-US/firefox/addon/netlas-io/
Google Netlas.io - Chrome Web Store The Netlas plugin gives information about where the website is hosted, who owns the IP and what other services and ports are open.
  • 🔥 2
  • 👾 2
Post #360 659
CVE-2025-25291, -25292 and other: Multiple vulnerabilitites in GitLab, 8.8 rating❗️

Traditionally, GitLab publishes information about several vulnerabilities at once. These include Interpretation Conflict, DoS, Credentials Disclose, etc.

Search at Netlas.io:
👉 Link: https://nt.ls/PDxYA
👉 Dork: http.favicon.hash_sha256:72a2cad5025aa931d6ea56c3201d1f18e68a8cd39788c7c80d5b2b82aa5143ef OR http.headers.set_cookie:"gitlab" OR http.headers.location:"gitlab"

Vendor's advisory: https://about.gitlab.com/releases/2025/03/12/patch-release-gitlab-17-9-2-released/
  • 🔥 3
  • 👾 3
Post #359 526
Netlas 1.1.0 is Here! 🚀

We've just rolled out a fresh update, fine-tuning Netlas for a smoother, more reliable experience.

📱 Mobile-Friendly: The Netlas app now plays nice with mobile devices
⚡️ Better Loading Experience: The IP/Domain Info Tool now shows a sleek skeleton page while loading
🐛 Bug Squash & Polish: We've tackled various issues under the hood.

Check out the full details here 👉 https://docs.netlas.io/changelog/
docs.netlas.io Changelog - Netlas Docs Explore the latest updates, enhancements, and fixes on the Netlas platform. Stay informed with our Changelog for all product and feature developments.
  • ❤ 2
  • 🔥 2
  • 👾 2
Post #358 479
CVE-2025-1661: Path Traversal in The HUSKY WordPress Plugin, 9.8 rating 🔥

The vulnerability allows an attacker to execute arbitrary files on the server, including PHP code.

Search at Netlas.io:
👉 Link: https://nt.ls/OEg7k
👉 Dork: http.body:"plugins/woocommerce-products-filter"

Read more: https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/woocommerce-products-filter/husky-products-filter-professional-for-woocommerce-1365-unauthenticated-local-file-inclusion
  • 🔥 3
  • 👾 3
  • 👍 1
Post #357 1.01K
CVE-2025-24813: Potential RCE in Apache Tomcat❗️

Deserialization of Untrusted Data and Path Equivalence vulnerabilities potentially allow an attacker to perform RCE or information disclosure.

Search at Netlas.io:
👉 Link: https://nt.ls/bzlj4
👉 Dork: http.favicon.hash_sha256:64a3170a912786e9eece7e347b58f36471cb9d0bc790697b216c61050e6b1f08 OR http.headers.server:"Apache-Coyote"

Vendor's advisory: https://lists.apache.org/thread/j5fkjv2k477os90nczf2v9l61fb0kkgq
  • 🔥 4
  • 👾 2
  • 👍 1
Post #356 516
❗️Temporary Issues with Private Scanner ❗️

While expanding disk space, we encountered unexpected issues that temporarily affected one of our servers. As a result, Private Scanner is currently unavailable. All other functions work properly.

Our team is actively working on a fix, and the service will be restored by the end of the week — possibly sooner.

We appreciate your patience and apologize for the inconvenience!
  • 💊 4
  • 🕊 2
Post #355 654
CVE-2025-27622, -27623, -27624, -27625: Multiple vulnerabilitites in Jenkins, medium rating❗️

The vulnerabilities allow attackers to view encrypted secret values ​​and potentially store attacker-controlled content in other users' profiles.

Search at Netlas.io:
👉 Link: https://nt.ls/SyXh2
👉 Dork: http.headers.x_jenkins:*

Vendor's advisory: https://www.jenkins.io/security/advisory/2025-03-05/
  • 🔥 3
  • 👾 3
  • 👍 1
Older posts →
Threads Profile ViewerView any public Threads profile without an account.Open ThreadLook →Writing with AI? Make it sound human.Metric37 rewrites AI drafts so they read naturally. Free AI detector, 1,500 words free.Try Metric37 →