Scantide Online
Scantide Intelligence

Default credential intelligence

Search documented factory and shared credentials for IoT devices, appliances and software, including clearly marked community suggestions. Scantide never attempts authentication, and these notices never affect the Scantide rating.

12,974 Credential records
1,740 Unique vendors
1,687 Unique passwords
686 Unique IoT models

Search credentials

Search by vendor, product, model, protocol, access level or username.

12974 credential-risk definitions are currently available.

System 75

Vendor:
· Model: System 75
unknown
41 campaign/advisory records
FBI / IC3 campaign / regional advisory intelligence — 20
00909f285745b657db9d9fe7
Multinational Non-Governmental Organizations Potentially Exploited in Aftermath of Earthquakes Affecting Turkey and Syria
01e9abcc28c68df5c0b4e43e
Update on SVR Cyber Operations and Vulnerability Exploitation
02c564e5d11e235eccef00f3
New Sandworm malware Cyclops Blink replaces VPNFilter
034b6dd4edcdf314784d621e
Unpatched and Outdated Medical Devices Provide Cyber Attack Opportunities
0698638c72fa1363ede20ec4
2021 Trends Show Increased Globalized Threat of Ransomware
07e7eb1322d4643ea3b7b3c7
Return to top
07e8dad684aa5ddf5f71550d
Motor Vehicles Increasingly Vulnerable to Remote Exploits
0a2ed3f904e1b539478b556c
APT40 Advisory: PRC MSS tradecraft in action
0bffb47abc37b910c5409e2d
Malicious Actors Almost Certainly Will Leverage Synthetic Content for Cyber and Foreign Influence Operations
0e29017b2b1f766d58fd49be
Malicious Cyber Actors Targeting Water and Wastewater Sector Internet- Facing Programmable Logic Controllers, Causing Operational Disruptions — FBI An official website of the United States government. Here's how you know Official websites use .gov A .gov website belongs to an official government organization in the United States. Secure .gov websites use HTTPS A lock ( ) or https:// means you've s
0e3e1f8fb7fb2135c147ed42
Countering Chinese State-Sponsored Actors Compromise of Networks Worldwide to Feed Global Espionage System — FBI An official website of the United States government. Here's how you know Official websites use .gov A .gov website belongs to an official government organization in the United States. Secure .gov websites use HTTPS A lock ( ) or https:// means you've safely connected to the .gov website
0f10cb84495aa2a8ce5570f8
Public Service Announcements
11c95addfb97b7069dc5873a
Compromise of Microsoft Exchange Server
11f725160c85af3ba01849cc
People's Republic of China State-Sponsored Cyber Actor Living off the Land to Evade Detection
1293a5f384189b121e72eaea
Suspected PRC Cyber Actors Continue to Globally Exploit Barracuda ESG Zero-Day Vulnerability
1499297aad75b4e344422d39
#StopRansomware: Royal Ransomware
15370f46fbce26b9a742d001
Criminal Actors Use Business Email Compromise to Steal Large Shipments of Food Products and Ingredients
17f78b216eee117ad2dfdf6e
Botnet/DDoS/TDoS
18b1a5dc6a6d45c83187f7ca
Tactics, Techniques, and Procedures of Indicted State-Sponsored Russian Cyber Actors Targeting the Energy Sector
18e9b4a33f64684443f98e6c
Malicious Actors Exploit CVE-2023-27350 in PaperCut MF and NG
CERT-EU campaign / regional advisory intelligence — 20
00fcbc2726cc1783631565f5
2021-034: Vulnerabilities in Cisco Products Friday, July 09, 2021 07:29:00 AM CEST On July 7, Cisco released security updates to address several security vulnerabilities. This list includes vulnerabilities rated High affecting Cisco Business Process Automation (BPA) with a CVSS score of 8.8 out of 10 and a vulnerability rated Medium affecting Cisco Adaptive Security Device Manager (ASDM) with a CVSS score of 7.5 out of 10.Vulnerabilities in Cisco Business Process Automation (BPA) could allow an
021dad8bb0c4c9076a95ac7d
2017-012: UPDATE! WannaCry Ransomware Campaign Exploiting SMB Vulnerability Monday, May 22, 2017 03:46:00 PM CEST A large ransomware campaign has been observed since Friday, May 12th, 2017. The payload delivered is a variant of ransomware malware called WannaCry. It appears to infect computers through a recent SMB vulnerability in Microsoft Windows operating system (CVE-2017-0145).
03b7a54ee5ce9e82f09fe828
Cyber Security Brief 23-09 - August 2023 Monday, September 04, 2023 12:20:00 PM CEST Cyber Security Briefs are monthly executive reports that aim to present an overview of the most relevant developments in cyber security, based exclusively on open sources, with a view to inform political leadership and senior management in its constituency. Additional information on any item in this Brief can be provided upon request. Cyber Security Briefs are TLP:CLEAR.
03f275e81a7d188dbbd18cbc
2018-011: Cisco Products Multiple Vulnerabilities Thursday, April 19, 2018 04:36:00 PM CEST On the 17th and 18th of April 2018, Cisco has released several updates to address vulnerabilities affecting multiple products in which a remote attacker can exploit these vulnerabilities to trigger cross site scripting, denial of service, remote code execution, security restriction bypass and sensitive information disclosure on the targeted system.
0463bc1aca415ae34bacd02a
2021-009: Critical Vulnerabilities in Cisco Products Thursday, February 04, 2021 09:35:00 PM CET Cisco has published an advisory about several vulnerabilities affecting various Cisco Products. These vulnerabilities could lead to remote code execution, privilege escalation, directory traversal, file overwrite or denial of service. While Cisco is not aware of any malicious exploit in the wild, it is highly recommended to patch the affected products.
04fc97c8f2852a360cdf4afc
2023
054ae807cc981d37171a388a
2012-0078: Multiple Buffer Overflow Vulnerabilities in the Cisco WebEx Player Monday, July 02, 2012 10:32:00 AM CEST The Cisco WebEx Recording Format (WRF) player contains four buffer overflow vulnerabilities and the Cisco Advanced Recording Format (ARF) player contains one buffer overflow vulnerability. In some cases,exploitation of the vulnerabilities could allow a remote attacker to execute arbitrary code on the system with the privileges of a targeted user.
057fdcd62e3ec018a2633e0f
2024-072: Vulnerabilities in Ivanti EPMM Monday, July 22, 2024 10:34:56 AM CEST On July 17, 2024, Ivanti released a security advisory addressing several vulnerabilities in its EPMM solution (formerly known as MobileIron). These vulnerabilities could lead to remote code execution, authentication bypass, and sensitive information leakage. It is recommended updating as soon as possible.
060783a8f0553c4295139910
Cyber Brief 25-04 - March 2025 Wednesday, April 02, 2025 04:00:00 PM CEST Cyber Briefs are monthly executive reports that aim to present an overview of the most relevant developments in cyber security, based exclusively on open sources, with a view to inform political leadership and senior management in its constituency. Additional information on any item in this Brief can be provided upon request. Cyber Briefs are TLP:CLEAR.
062b7209b6e24bd336bba3e4
2025-025: Critical Vulnerabilities in Cisco ISE Friday, July 18, 2025 02:57:21 PM CEST On June 25, Cisco released an advisory addressing 2 critical vulnerabilities affecting Cisco's Identity Services Engine (ISE) product that would allow an attacker to execute arbitrary code on vulnerable devices. On July 16, Cisco updated this advisory adding a third critical vulnerability affecting Cisco's Identity Services Engine (ISE) product. It is recommended updating affected product as soon as possible.
07411bcf604e25db68ae4f02
2023-003: Critical Vulnerability in VMware vRealize Log Insight Thursday, January 26, 2023 11:55:00 AM CET On January 24, 2022, VMWare released a new security advisory revealing multiple vulnerabilities in VMware vRealize Log Insight. There are two critical vulnerabilities including a directory traversal vulnerability (CVE-2022-31706) and a broken access control vulnerability (CVE-2022-31704). Both of them have the CVSS score of 9.8 out of 10. It is highly recommended applying the last version.
07a28d190f41f960bd15cf9a
Cyber Brief - July 2022 Tuesday, August 02, 2022 10:17:00 AM CEST Cyber Briefs are monthly executive reports that aim to present an overview of the most relevant developments in cyber security, based exclusively on open sources, with a view to inform political leadership and senior management in its constituency. Additional information on any item in this Brief can be provided upon request. Cyber Briefs are TLP:WHITE.
07f93ac177a174d99635789b
2020-036: Critical Cisco Vulnerabilities Thursday, July 16, 2020 12:06:00 PM CEST Cisco released 31 Security Advisories for vulnerabilities affecting its products. Five of them are rated critical with CVSS Score 9.8. In particular, critical vulnerabilities affect: telnet service of firewall routers (CVE-2020-3330), web-based management interface of routers (CVE-2020-3323, CVE-2020-3144, and CVE-2020-3331), and web management interface of Cisco Prime License Manager (PLM) software (CVE-2020-3140)
08af8e105c397ab708b7e1a4
Cyber Brief 24-11 - October 2024 Monday, November 04, 2024 05:00:00 PM CET Cyber Briefs are monthly executive reports that aim to present an overview of the most relevant developments in cyber security, based exclusively on open sources, with a view to inform political leadership and senior management in its constituency. Additional information on any item in this Brief can be provided upon request. Cyber Security Briefs are TLP:CLEAR.
0954b1e79e4ef36be423c289
2012-0074: Jboss Security Update - JNDI: unauthenticated remote write access is permitted by default Friday, June 22, 2012 02:12:00 PM CEST An update that fixes one security issue is now available from the Red Hat Customer Portal.The Red Hat Security Response Team has rated this update as having important security impact. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating,is available from the CVE link in the References section.
0a56d52387d7c2a6a62c3e2a
2020-052: Critical Cisco IOS XR Software Vulnerability Under Attack Wednesday, October 21, 2020 02:46:00 PM CEST Cisco released a warning on the 20th of October regarding the attacks that are actively targeting the CVE-2020-3118 high severity vulnerability found to affect multiple carrier-grade routers that run the company's Cisco IOS XR Software. An advisory for this vulnerability was released by Cisco in the 5th of February. It is related to the Cisco Discovery Protocol implementation for Cisc
0a60241a2ab097d6dfe3907e
2024-028: Vulnerabilities in Fortinet Products Thursday, March 14, 2024 05:49:32 PM CET On March 12, 2024, Fortinet released fixes for three vulnerabilities affecting some of their products. The vulnerabilities could allow an unauthenticated attacker to execute unauthorised code or commands via specifically crafted requests. It is recommended upgrading affected software as soon as possible.
0a908630597550ae16e822f1
2022-046: Critical PHP Flaw Exposes QNAP NAS Devices to RCE Attacks Wednesday, June 22, 2022 06:36:00 PM CEST On 22nd of June 2022, QNAP published an advisory about specific products that are vulnerable to remote code execution (RCE) when certain conditions are met. The CVE-2019-11043 is reported to affect PHP versions 7.1.x below 7.1.33, 7.2.x below 7.2.24 and 7.3.x below 7.3.11. In certain configurations of FPM setup, it is possible to cause FPM module to write past allocated buffers into the
0f6144d791dc06347d6ae92f
2021-035: Multiple Palo Alto Vulnerabilities Thursday, July 15, 2021 03:01:00 PM CEST On July 14, Palo Alto published security advisories about two vulnerabilities rated as high, CVE-2021-3042 and CVE-2021-3044, affecting respectively Cortex XDR Agent and Prisma Cloud.
100bdd71ea7bd8e5ed96180d
2021-015: UPDATE: Critical Vulnerabilities Affecting F5 Devices Thursday, March 11, 2021 09:30:00 AM CET On the 10th or March 2021, F5 released several security advisories, including four identified as critical.One of the vulnerabilities allows an unauthenticated attacker with network access to the iControl REST interface, through the BIG-IP management interface and self IP addresses, to execute arbitrary system commands, create or delete files, and disable services.Another of the vulnerabilitie
Europol / EC3 campaign / regional advisory intelligence — 1
276787228e3814ccbb0b0f56
FS-ISAC and Europol Partner to Combat Cross-Border Cybercrime – Europol’s EC3 signs Memorandum of Understanding (MOU) with global non-profit dedicated to reducing cyber-risk in the financial system through intelligence sharing. | Europol You need to enable JavaScript to run this app. Loading application. Please wait.
craft : craft

Public sources document default credentials associated with this vendor or product. No login attempt was performed.

Source: scantide_default_credentials
References

CellPlex

Vendor:
· Model: CellPlex
telnet
tech : [blank]

Public sources document default credentials associated with this vendor or product. No login attempt was performed.

Source: scantide_default_credentials
References

Switch PowerConnect

Vendor:
· Model: Switch PowerConnect
unknown
34 campaign/advisory records
FBI / IC3 campaign / regional advisory intelligence — 12
9883cca01b447c711eb32c12
#StopRansomware: Black Basta
0e29017b2b1f766d58fd49be
Malicious Cyber Actors Targeting Water and Wastewater Sector Internet- Facing Programmable Logic Controllers, Causing Operational Disruptions — FBI An official website of the United States government. Here's how you know Official websites use .gov A .gov website belongs to an official government organization in the United States. Secure .gov websites use HTTPS A lock ( ) or https:// means you've s
18b1a5dc6a6d45c83187f7ca
Tactics, Techniques, and Procedures of Indicted State-Sponsored Russian Cyber Actors Targeting the Energy Sector
5ea95b5b3e54b76916c70a29
Criminals Increasing SIM Swap Schemes to Steal Millions of Dollars from US Public
6df771d5782fae9ddbbb04bf
Addressing Risks Associated with Rail Industrial Internet of Things and Commercial Off-the-Shelf System Solutions
970ffe8aeb92ab57cc0fe1aa
TRITON Malware Remains Threat to Global Critical Infrastructure Industrial Control Systems (ICS)
FBI_IC3-260407.pdf
TLP:CLEAR Co-Authored by: Product ID: AA26-097A Iranian-Affiliated Cyber Actors Exploit Programmable Logic Controllers Across US Critical Infrastructure Publication: April 7, 2026 Federal Bureau of Investigation Cybersecurity and Infrastruc
FBI_IC3-260722.pdf
TLP:CLEAR Co-Authored by: Product ID: AA26-097A Iranian-Affiliated Cyber Actors Exploit Programmable Logic Controllers Across US Critical Infrastructure Publication: April 7, 2026 Last Update: July 22, 2026 Federal Bureau of Investigation D
FBI_IC3-PSA260730.pdf
Alert: I-073026-PSA | 30 JULY 2026 Malicious Cyber Actors Targeting Water and Wastewater Sector Internet- Facing Programmable Logic Controllers, Causing Operational Disruptions INTRODUCTION The Federal Bureau of Investigation (FBI) and Envi
ad7c1093c9fdf6aca1f7cb38
Risk Management for Electronic Ballot Delivery, Marking, and Return
d739e7f21758c959e3826e34
Mitigating Log4Shell and Other Log4j-Related Vulnerabilities
dcc3eb16963e92b8e0c4641b
Tactics, Techniques, and Procedures Associated with Malware within Chinese Government-Mandated Tax Software
CERT-EU campaign / regional advisory intelligence — 20
4cfdc6f8f9029a0a5eb188b4
2021-022: Insufficient Access Control Vulnerability in the Dell Driver Wednesday, May 05, 2021 12:30:00 PM CEST On the 5th of May 2021, Dell has released a security advisory to address multiple vulnerabilities. Those could be exploited by attackers to access driver functions and execute malicious code with kernel-mode privileges.
5a84a2d6ff686f88874206e7
Cyber Brief 24-06 - May 2024 Monday, June 03, 2024 06:00:00 PM CEST Cyber Briefs are monthly executive reports that aim to present an overview of the most relevant developments in cyber security, based exclusively on open sources, with a view to inform political leadership and senior management in its constituency. Additional information on any item in this Brief can be provided upon request. Cyber Security Briefs are TLP:CLEAR.
6350fe51a8e40e4f490446ae
Cyber Brief 25-08 - July 2025 Monday, August 04, 2025 11:00:00 AM CEST Cyber Briefs are monthly executive reports that aim to present an overview of the most relevant developments in cyber security, based exclusively on open sources, with a view to inform political leadership and senior management in its constituency. Additional information on any item in this Brief can be provided upon request. Cyber Briefs are TLP:CLEAR.
a3669f25439ea71ed1983d8c
2012-0138: Samsung and some Dell printers, Remote Disclosure of Information. Thursday, December 06, 2012 10:06:00 AM CET Samsung printers and some Dell printers manufactured for Samsung contain and snmp account that could be used to get privileged access to the devices.
a500fa4a29ad57aa65c33eb3
2015
b83e6625c71f56cad006c24a
2021-031: Critical Vulnerability in DELL BIOSConnect Tuesday, June 29, 2021 09:27:00 AM CEST On 24th of June 2021, Dell released a client platform security update for multiple vulnerabilities in the BIOSConnect and HTTPS Boot features as part of the Dell Client BIOS. The chain of vulnerabilities has a cumulative CVSS score of 8.3 (High) because it allows a privileged network adversary to impersonate "dell.com" and gain arbitrary code execution at the BIOS/UEFI level of the affected device. This
de704e1e5302955ec55869fe
Cyber Brief 24-10 - September 2024 Tuesday, October 01, 2024 06:00:00 PM CEST Cyber Briefs are monthly executive reports that aim to present an overview of the most relevant developments in cyber security, based exclusively on open sources, with a view to inform political leadership and senior management in its constituency. Additional information on any item in this Brief can be provided upon request. Cyber Security Briefs are TLP:CLEAR.
decebe71a58113ba6e5f1c3b
2012
e6c483442b0d418eb4cdea97
2015-750: Vulnerable Dell Self-Signed Root certificates Tuesday, November 24, 2015 04:11:00 PM CET Some Dell laptops and desktops come with a pre-installed self-signed root certificate under the name of eDellRoot and in some occasions have also an installed another self-signed root certificate under the name of DSDTestProvider. This is a potential security vulnerability that makes it easy for attackers to hijack Internet connections and masquerade as trusted websites. That security vulnerability
ed09786a3d6bd296872c16a5
Cyber Brief 26-03 - February 2026 Monday, March 02, 2026 06:00:00 PM CET Cyber Briefs are monthly executive reports that aim to present an overview of the most relevant developments in cyber security, based exclusively on open sources, with a view to inform political leadership and senior management in its constituency. Additional information on any item in this Brief can be provided upon request. Cyber Briefs are TLP:CLEAR.
321c02670655f8a44a3a02d6
2017-003: CISCO Smart Install Protocol Issues Wednesday, February 22, 2017 03:28:00 PM CET It has been reported that there exists a way to misuse the Cisco Smart Install protocol messages. The misuse is directed towards Smart Install Clients allowing an unauthenticated remote attacker to change the startup configuration, load alternative IOS versions, and execute commands on affected devices. Cisco does not consider this issue a vulnerability. However, since Cisco Smart Install is enabled by def
579a8b2540f682b380dc70a2
Cyber Brief 25-10 - September 2025 Wednesday, October 01, 2025 05:00:00 PM CEST Cyber Briefs are monthly executive reports that aim to present an overview of the most relevant developments in cyber security, based exclusively on open sources, with a view to inform political leadership and senior management in its constituency. Additional information on any item in this Brief can be provided upon request. Cyber Briefs are TLP:CLEAR.
863a0d28df38c4f7b62953c7
Cyber Brief - August 2022 Monday, October 03, 2022 10:10:00 PM CEST Cyber Briefs are monthly executive reports that aim to present an overview of the most relevant developments in cyber security, based exclusively on open sources, with a view to inform political leadership and senior management in its constituency. Additional information on any item in this Brief can be provided upon request. Cyber Briefs are TLP:WHITE.
880c62e58e29fb1916e3bd13
Cyber Security Brief 23-12 - November 2023 Monday, December 04, 2023 10:25:00 AM CET Cyber Security Briefs are monthly executive reports that aim to present an overview of the most relevant developments in cyber security, based exclusively on open sources, with a view to inform political leadership and senior management in its constituency. Additional information on any item in this Brief can be provided upon request. Cyber Security Briefs are TLP:WHITE.
98bfc71e092d2db76184aba5
2023-011: ClamAV critical vulnerability Monday, February 20, 2023 03:40:00 PM CET On February 15th, 2023, ClamAV informed about a critical vulnerability in the cross-platform antimalware toolkit. The vulnerability is identified as CVE-2023-20032 and could lead to remote code execution.
ae9799fa4658d0484d5adbc8
Cyber Brief 26-08 - July 2026 Monday, August 03, 2026 05:00:00 PM CEST Cyber Briefs are monthly executive reports that aim to present an overview of the most relevant developments in cyber security, based exclusively on open sources, with a view to inform political leadership and senior management in its constituency. Additional information on any item in this Brief can be provided upon request. Cyber Briefs are TLP:CLEAR.
c94464fc9643d2f58895997a
2017-014: Petya-Like Malware Campaign Wednesday, June 28, 2017 11:34:00 AM CEST A large malware campaign broke out on Tuesday, 27/06/2017 and was widely reported in the news. The malware used -- which appears to be similar to Petya -- has been augmented with efficient local network spreading mechanisms, which resulted in a very rapid infection rate inside affected organizations. The local propagation is apparently achieved by a combination of the use of EternalBlue (the same exploit as the one u
ce9c8808f75fe5ce6170d24c
2021-042: Critical Vulnerability in Microsoft Hyper-V Thursday, July 29, 2021 09:23:00 PM CEST On May 11, Microsoft published a security update guide about a critical Hyper-V Remote Code Execution Vulnerability, tracked as "CVE-2021-28476" with a CVSS score of 9.9. The exploitation of this vulnerability can lead to denial of service conditions or remote code execution. A proof of concept for this vulnerability is now publicly available.
d2a09ba23b503c7248ce411a
Cyber Security Brief 23-04 - March 2023 Monday, April 03, 2023 03:15:00 PM CEST Cyber Security Briefs are monthly executive reports that aim to present an overview of the most relevant developments in cyber security, based exclusively on open sources, with a view to inform political leadership and senior management in its constituency. Additional information on any item in this Brief can be provided upon request. Cyber Security Briefs are TLP:CLEAR.
ea61f1a5c038c8c69b6b9bd6
Cyber Brief 26-06 - May 2026 Tuesday, June 02, 2026 06:00:00 PM CEST Cyber Briefs are monthly executive reports that aim to present an overview of the most relevant developments in cyber security, based exclusively on open sources, with a view to inform political leadership and senior management in its constituency. Additional information on any item in this Brief can be provided upon request. Cyber Briefs are TLP:CLEAR.
JVN / Japan campaign / regional advisory intelligence — 2
JVNDB-2015-000176
SonicWall TotalSecure TZ 100 Series vulnerable to denial-of-service (DoS)
Published 2015-11-06T12:30:02+09:00
JVNDB-2026-000032
Multiple vulnerabilities in Dell UPS Multi-UPS Management Console (MUMC)
Published 2026-03-04T12:20:42+09:00
admin : admin

Public sources document default credentials associated with this vendor or product. No login attempt was performed.

Source: scantide_default_credentials

Brother

Vendor:
unknown
9 campaign/advisory records
JVN / Japan campaign / regional advisory intelligence — 9
JVNDB-2023-001894
Android App "Brother iPrint&Scan" vulnerable to improper access control
Published 2023-05-19T15:40:27+09:00
JVNDB-2023-014781
Brother iPrint&Scan Desktop for Windows vulnerable to improper link resolution before file access
Published 2023-12-26T09:27:27+09:00
JVNDB-2025-021305
Android App "Brother iPrint&Scan" improper use of an external cache directory
Published 2025-12-09T17:25:32+09:00
JVNDB-2017-000160
MFC-J960DWN vulnerable to cross-site request forgery
Published 2017-07-04T13:59:02+09:00
JVNDB-2023-002270
Null pointer dereference vulnerability in multiple printers and MFPs which implement BROTHER debut web server
Published 2023-06-30T11:49:12+09:00
JVNDB-2024-000026
Multiple vulnerabilities in printers and scanners which implement BROTHER Web Based Management
Published 2024-03-06T18:12:42+09:00
JVNDB-2025-014081
Multiple Brother and its OEM products with weak initial administrator passwords
Published 2025-09-19T10:52:57+09:00
JVNDB-2026-001732
Multiple Brother software installers may insecurely load Dynamic Link Libraries
Published 2026-01-26T16:04:00+09:00
JVNDB-2026-002119
Multiple vulnerabilities in BROTHER MFPs (multifunction printers)
Published 2026-01-30T11:26:11+09:00
admin : [blank]

Public sources document default credentials associated with this vendor or product. No login attempt was performed.

Source: scantide_default_credentials

OS/400

Vendor:
· Model: OS/400
multi
26 campaign/advisory records
FBI / IC3 campaign / regional advisory intelligence — 1
36b4ec7d77002ad7f7aa6d7e
Guidelines for secure AI system development
CERT-EU campaign / regional advisory intelligence — 6
5cc2ed95629003380b8e47d0
2011
9c97832c4deff24c44466de4
Cyber Security Brief 23-08 - July 2023 Tuesday, August 01, 2023 08:30:00 PM CEST Cyber Security Briefs are monthly executive reports that aim to present an overview of the most relevant developments in cyber security, based exclusively on open sources, with a view to inform political leadership and senior management in its constituency. Additional information on any item in this Brief can be provided upon request. Cyber Security Briefs are TLP:CLEAR.
a07ff9c64a8eaaac05972609
2012-0102: IBM WebSphere MQ File Transfer Edition Web Gateway insufficient access control Friday, August 17, 2012 03:34:00 PM CEST When using the web gateway, an authenticated user is able to access other users' files without further access control if the URL of the file is known. The URL for a file contains non guessable elements.
decebe71a58113ba6e5f1c3b
2012
e4d65c698fc358af977b08bd
Cyber Security Brief 24-04 - March 2024 Wednesday, April 03, 2024 12:30:00 PM CEST Cyber Security Briefs are monthly executive reports that aim to present an overview of the most relevant developments in cyber security, based exclusively on open sources, with a view to inform political leadership and senior management in its constituency. Additional information on any item in this Brief can be provided upon request. Cyber Security Briefs are TLP:CLEAR.
ea61f1a5c038c8c69b6b9bd6
Cyber Brief 26-06 - May 2026 Tuesday, June 02, 2026 06:00:00 PM CEST Cyber Briefs are monthly executive reports that aim to present an overview of the most relevant developments in cyber security, based exclusively on open sources, with a view to inform political leadership and senior management in its constituency. Additional information on any item in this Brief can be provided upon request. Cyber Briefs are TLP:CLEAR.
JVN / Japan campaign / regional advisory intelligence — 19
JVNDB-2005-000705
Fujitsu Java Runtime Environment reflection API vulnerability
Published 2008-05-21T00:00:00+09:00
JVNDB-2005-000706
Fujitsu Java Runtime Environment reflection API vulnerability
Published 2008-05-21T00:00:00+09:00
JVNDB-2005-000707
Fujitsu Java Runtime Environment reflection API vulnerability
Published 2008-05-21T00:00:00+09:00
JVNDB-2005-000727
mod_imap cross-site scripting vulnerability
Published 2008-05-21T00:00:00+09:00
JVNDB-2005-000776
Java Cryptography Extension 1.2.1 (JCE 1.2.1) will no longer function properly after July 28, 2005 due to the expiration of its digital certificate
Published 2008-05-21T00:00:00+09:00
JVNDB-2007-000802
Lotus Domino cross-site scripting vulnerability
Published 2008-05-21T00:00:00+09:00
JVNDB-2007-000819
Cross-site scripting vulnerability in Apache HTTP Server "mod_imap" and "mod_imagemap"
Published 2008-05-21T00:00:00+09:00
JVNDB-2008-001043
X.Org Foundation X server buffer overflow vulnerability
Published 2008-06-13T17:11:26+09:00
JVNDB-2011-000016
IBM DB2 vulnerable to denial-of-service (DoS)
Published 2011-03-04T19:29:37+09:00
JVNDB-2011-000017
IBM WebSphere Application Server vulnerable to denial-of-service (DoS)
Published 2011-03-04T19:29:20+09:00
JVNDB-2011-000018
IBM Lotus vulnerable to denial-of-service (DoS)
Published 2011-03-04T19:28:42+09:00
JVNDB-2013-000004
WebSphere Application Server (WAS) vulnerable to cross-site scripting
Published 2013-01-25T12:32:36+09:00
JVNDB-2013-000030
Lotus Domino vulnerable to denial-of-service (DoS)
Published 2013-03-28T12:32:39+09:00
JVNDB-2013-000070
Oracle Outside In vulnerable to buffer overflow
Published 2013-07-17T13:45:49+09:00
JVNDB-2013-000071
Oracle Outside In vulnerable to denial-of-service (DoS)
Published 2013-07-17T13:56:43+09:00
JVNDB-2026-000038
Installer for IBM Trusteer Rapport may insecurely load Dynamic Link Libraries
Published 2026-03-17T14:57:53+09:00
JVNDB-2007-000395
Homepage Builder sample CGI programs vulnerable to OS command injection
Published 2008-05-21T00:00:00+09:00
JVNDB-2008-000011
Internet Scanner reporting engine vulnerable to cross-site scripting
Published 2008-05-21T00:00:00+09:00
JVNDB-2025-000104
Multiple vulnerabilities in GNU Libmicrohttpd
Published 2025-11-10T15:07:35+09:00
qsecofr : 22222222

Public sources document default credentials associated with this vendor or product. No login attempt was performed.

Source: scantide_default_credentials

Terminal Server

Vendor:
· Model: Terminal Server
port_7000
11 campaign/advisory records
FBI / IC3 campaign / regional advisory intelligence — 6
2d8d9bc13ebc018f2f442e1b
Top Cyber Actions for Securing Water Systems
402a4bd5a88cb97b7cc84f00
Cybersecurity Guidance: Chinese-Manufactured UAS
7552923fc476335081e148e7
Enhanced Visibility and Hardening Guidance for Communications Infrastructure
90bad38ebb1c7aa5decba7d3
Context and Recommendations to Protect Against Malicious Activity by Iranian Cyber Group Emennet Pasargad
FBI_IC3-260818.pdf
TLP:CLEAR Co-Authored by: Product ID: AA25-071A #StopRansomware: Medusa Ransomware Publication: March 12, 2025 Last Updated: August 18, 2026 Cybersecurity and Infrastructure Security Agency Federal Bureau of Investigation Department of Heal
e600ad5f025c7db5d4a76554
Emerging Hospice Fraud Targeting Medicare Recipients
CERT-EU campaign / regional advisory intelligence — 5
57290228ca09d11606e01c27
2019-013: UPDATED 07/2019: Remote Desktop Services -- Remote Code Execution Vulnerability Thursday, May 16, 2019 04:22:00 PM CEST Microsoft released fixes for a critical Remote Code Execution vulnerability (CVE-2019-0708) in Remote Desktop Services that affects some older versions of Windows. The vulnerability has been since named BlueKeep.The Remote Desktop Protocol (RDP) itself is not vulnerable. This vulnerability is pre-authentication and requires no user interaction. In other words, the vul
604daa5eb674207d00364f2c
2019-003: RunC Vulnerability Affecting Container Management Systems Wednesday, February 13, 2019 01:58:00 PM CET A container breakout security flaw was found in underlying software used by _containerization_ software (operating-system-level virtualization software). The vulnerability - CVE-2019-5736 - dubbed "runc container breakout" allows specially crafted containers to gain administrative privileges on the host. Exploits for this vulnerability are already circulating in the wild.
a213934382942b68466c7b7e
2021-051: Critical Vulnerabilities in Azure OMI Agents Wednesday, September 15, 2021 01:59:00 PM CEST On 14th of September 2021, Microsoft released information about four vulnerabilities that affects Open Management Infrastructure (OMI) agent.One vulnerability - CVE-2021-38647 - is critical with CVSSv3 Score 9.8. If the HTTP/S port listening to OMI is exposed, it could allow remote code execution by sending a specially-crafted message from remote.The other three vulnerabilities - CVE-2021-38645,
a5bff4b339cfb411cb4ac0f5
2024-076: Vulnerabilities in OpenVPN Monday, August 12, 2024 03:31:53 PM CEST On March 20, 2024, the OpenVPN community project team disclosed several vulnerabilities, CVE-2024-27459, CVE-2024-24974, CVE-2024-27903 and CVE-2024-1305 that could be chained to achieve remote code execution (RCE) and local privilege escalation (LPE). On August 8, 2024, Microsoft released a writeup for those vulnerabilities.
ea9d453462a9b74cf29d2ca1
2018-020: Speculative Execution Attack on Intel Processors Friday, August 17, 2018 10:04:00 AM CEST In January 2018, two separate teams discovered flaws in Intel processorallowing speculative execution attacks and notified Intel of their researches. On 14th of August 2018, the vulnerabilities were disclosed publicly under the name Foreshadow. Based on the provided technical details Intel investigated further and identified two other attack channel with the potential to impact additional micropro
[no username] : access

Public sources document default credentials associated with this vendor or product. No login attempt was performed.

Source: scantide_default_credentials
References

stratacom

Vendor:
unknown
stratacom : [blank]

Public sources document default credentials associated with this vendor or product. No login attempt was performed.

Source: scantide_default_credentials

Power IQ

Vendor:
· Model: Power IQ
http
1 credential CWE signal 1 CVE · highest 8.4 41 campaign/advisory records
Credential weakness intelligence

CVE/CWE correlation for this exact matched product/device indicates credential-handling weaknesses. This does not mean Scantide has a documented usable password unless a credential record above explicitly provides one.

Hard-coded credentials CWE-798
Evidence comes from 1 matched CVE.
CVEs matching this vendor/product — 1 Highest CVSS 8.4
CVSS 8.4 EPSS 0.1% CISA CSAF 2 EUVD 1 Vulnrichment GHSA 1
Sunbird DCIM dcTrack and Power IQ Use of Hard-coded Credentials
Published 2025-12-04T21:02:59.614Z Updated 2026-06-04T20:05:57.617Z CWE-798
Hard-coded credentials CWE-798
FBI / IC3 campaign / regional advisory intelligence — 20
FBI_IC3-260826.pdf
TLP:CLEAR Co-Authored by: ID: JCSA-20260826-01 China-Linked Hacking Group QTFY Targets Military and Critical Infrastructure with Malicious Distributed Systems To report suspicious or criminal activity related to information found in this jo
15370f46fbce26b9a742d001
Criminal Actors Use Business Email Compromise to Steal Large Shipments of Food Products and Ingredients
1a89e7cf2bfa6441030da3d1
Incident Response Guide: Water and Wastewater Sector
25091f9b0f59b31c2bd98141
Iranian State Actors Conduct Cyber Operations Against the Government of Albania
2becd729f39ba0f44afaf582
People's Republic of China-Linked Cyber Actors Hide in Router Firmware
47bbd1d17f59c7f340bfc49f
#StopRansomware: Cuba Ransomware
57ff43de10c50b891ba950cf
Top CVEs Actively Exploited By People's Republic of China State-Sponsored Cyber Actors
64af8dcd0e3c1ba4ef460821
2025
725c462d3770cd1d7ac5d167
Skip to content
8252636e4f1918a10e064cb1
File A Complaint
9550066e70010a432e19c33e
People's Republic of China-Linked Actors Compromise Routers and IoT Devices for Botnet Operations
a1ec2d34be04b293b9297f23
#StopRansomware: LockBit 3.0 Ransomware Affiliates Exploit CVE 2023-4966 Citrix Bleed Vulnerability
a4b2d73caacf58c5bd9c5fcf
Funnull Technology Inc. Associated CNAMEs
c7f3885a35b7b6c4b4959f7c
TraderTraitor: North Korean State-Sponsored APT Targets Blockchain Companies
e20824ffecee41239349de94
Office of Public Affairs | Two U.S. Nationals Sentenced for Facilitating Fraudulent Remote Information Technology Worker Schemes to Generate Revenue for the Democratic People’s Republic of Korea | United States Department of Justice Skip to main content An official website of the United States government Here's how you know Here's how you know Official websites use .gov A .gov website belongs to a
0c53d81fe5295ed5bf1e751f
Foreign Cyber Actors Target Home and Office Routers and Networked Devices Worldwide
11c95addfb97b7069dc5873a
Compromise of Microsoft Exchange Server
18ea7a6458253a663ccafb8d
Office of Public Affairs | Justice Department Announces Coordinated, Nationwide Actions to Combat North Korean Remote Information Technology Workers’ Illicit Revenue Generation Schemes | United States Department of Justice Skip to main content An official website of the United States government Here's how you know Here's how you know Official websites use .gov A .gov website belongs to an official
3b9501c48a020703b53d896c
The FBI and Intellectual Property Rights Center Warns Public of Counterfeit Battery Scams
3cf3abac6a50ac70e5372abd
#StopRansomware Guide
CERT-EU campaign / regional advisory intelligence — 20
6c02dd9198476af5eb61710d
2019-007: UPDATE: Operation ShadowHammer – Compromised ASUS Computers Tuesday, March 26, 2019 12:17:00 PM CET In January 2019, Kaspersky has discovered a supply chain attack that affects ASUS computers. Dubbed Operation ShadowHammer, the operation took place from June to November 2018. It is similar to other supply chain attacks on Netsarang and CCleaner. Around 500 thousands of computers could have been potentially impacted, although the malware seems to have been only targeting a few hundred (
7a76ec138c3cb3d05aad4ac6
2013-0001: Fraudulent certificates issued by Trusted CA impact on Microsoft products and other Browser products Monday, January 07, 2013 03:36:00 PM CET CERT-EU has been made aware of a security issue related to certificates issued by TURKTRUST Inc. TURKTRUST Inc is certificate provider which CA is included in several trusted CA databases used by products like browsers. Consequently, fraudulent certificates can be issued and be used to impersonate server and sites. A fraudulent certificate has b
042b47402abed19d6571e06a
Airports & Operational Technology: 4 Attack Scenarios Wednesday, July 24, 2019 11:27:00 AM CEST - Security in global aviation is increasingly dependent on vulnerabilities in information technology (IT) and operational technology (OT) systems.- Airports are using several critical OT systems (e.g. baggage control, runway lights, air conditioning, and power).- More than a hundred unique exploits have been spotted since the publication of proofs of concept and payload creation tools, after the discl
40bd775e38586aabc60b91ae
Cyber Security Brief 24-01 - December 2023 Friday, January 05, 2024 04:00:00 PM CET Cyber Security Briefs are monthly executive reports that aim to present an overview of the most relevant developments in cyber security, based exclusively on open sources, with a view to inform political leadership and senior management in its constituency. Additional information on any item in this Brief can be provided upon request. Cyber Security Briefs are TLP:WHITE.
46018dedebc8c36b882cdd46
Annual Conference
4d4f16e2615739a41610afc4
Cyber Brief - June 2022 Friday, July 01, 2022 03:15:00 PM CEST Cyber Briefs are monthly executive reports that aim to present an overview of the most relevant developments in cyber security, based exclusively on open sources, with a view to inform political leadership and senior management in its constituency. Additional information on any item in this Brief can be provided upon request. Cyber Briefs are TLP:WHITE.
522a288ee1b7b3f828225d33
About us
7a8af3c6f57edf032a0f70fa
Cyber Security Brief - November 2022 Thursday, December 01, 2022 11:20:00 AM CET Cyber Security Briefs are monthly executive reports that aim to present an overview of the most relevant developments in cyber security, based exclusively on open sources, with a view to inform political leadership and senior management in its constituency. Additional information on any item in this Brief can be provided upon request. Cyber Security Briefs are TLP:WHITE.
81584383d86765a515d350e9
Cyber Security Brief 23-06 - May 2023 Thursday, June 01, 2023 04:20:00 PM CEST Cyber Security Briefs are monthly executive reports that aim to present an overview of the most relevant developments in cyber security, based exclusively on open sources, with a view to inform political leadership and senior management in its constituency. Additional information on any item in this Brief can be provided upon request. Cyber Security Briefs are TLP:CLEAR.
86251db72d0820ed370d3d7c
Cyber Brief 26-02 - January 2026 Monday, February 02, 2026 04:30:00 PM CET Cyber Briefs are monthly executive reports that aim to present an overview of the most relevant developments in cyber security, based exclusively on open sources, with a view to inform political leadership and senior management in its constituency. Additional information on any item in this Brief can be provided upon request. Cyber Briefs are TLP:CLEAR.
86815da7a958e2034e64e35f
US & Russia mutually targeting their power grids Wednesday, July 24, 2019 11:42:00 AM CEST - A New York Times report alleges that the US has infiltrated the Russian electrical grid with offensive malware.- The infiltration is not known to have been linked with any disruption.- If the report is true, this activity poses risks of escalation and retaliation.- A separate report by a security company indicates that a Russian threat group is probing US and Asian electrical grids.
87a7e620239146883ecd0751
Cyber Brief 25-03 - February 2025 Monday, March 03, 2025 05:00:00 PM CET Cyber Briefs are monthly executive reports that aim to present an overview of the most relevant developments in cyber security, based exclusively on open sources, with a view to inform political leadership and senior management in its constituency. Additional information on any item in this Brief can be provided upon request. Cyber Briefs are TLP:CLEAR.
880c62e58e29fb1916e3bd13
Cyber Security Brief 23-12 - November 2023 Monday, December 04, 2023 10:25:00 AM CET Cyber Security Briefs are monthly executive reports that aim to present an overview of the most relevant developments in cyber security, based exclusively on open sources, with a view to inform political leadership and senior management in its constituency. Additional information on any item in this Brief can be provided upon request. Cyber Security Briefs are TLP:WHITE.
9136a85af7dac9f7b449484e
TLR 10 Years
a238646c9a2dff1dadd9b4f3
Cyber Brief 25-06 - May 2025 Tuesday, June 03, 2025 04:30:00 PM CEST Cyber Briefs are monthly executive reports that aim to present an overview of the most relevant developments in cyber security, based exclusively on open sources, with a view to inform political leadership and senior management in its constituency. Additional information on any item in this Brief can be provided upon request. Cyber Briefs are TLP:CLEAR.
a3a313b9c58875d65b2979ea
Cyber Security Brief - December 2022 Tuesday, January 03, 2023 02:50:00 PM CET Cyber Security Briefs are monthly executive reports that aim to present an overview of the most relevant developments in cyber security, based exclusively on open sources, with a view to inform political leadership and senior management in its constituency. Additional information on any item in this Brief can be provided upon request. Cyber Security Briefs are TLP:WHITE.
acaa11ab8c54478bdf11017c
Cyber Brief 26-01 - December 2025 Monday, January 05, 2026 04:00:00 PM CET Cyber Briefs are monthly executive reports that aim to present an overview of the most relevant developments in cyber security, based exclusively on open sources, with a view to inform political leadership and senior management in its constituency. Additional information on any item in this Brief can be provided upon request. Cyber Briefs are TLP:CLEAR.
b3384778dc49dc28ed930803
Cyber Security Brief - October 2022 Thursday, November 03, 2022 10:50:00 AM CET Cyber Security Briefs are monthly executive reports that aim to present an overview of the most relevant developments in cyber security, based exclusively on open sources, with a view to inform political leadership and senior management in its constituency. Additional information on any item in this Brief can be provided upon request. Cyber Security Briefs are TLP:WHITE.
bb5954374c2e36c70c022b6d
Cyber Brief 25-01 - December 2024 Friday, January 03, 2025 04:00:00 PM CET Cyber Briefs are monthly executive reports that aim to present an overview of the most relevant developments in cyber security, based exclusively on open sources, with a view to inform political leadership and senior management in its constituency. Additional information on any item in this Brief can be provided upon request. Cyber Briefs are TLP:CLEAR.
cd78ff783f36db815eeb1c8c
Cyber Brief - May 2022 Wednesday, June 01, 2022 02:08:00 PM CEST Cyber Briefs are monthly executive reports that aim to present an overview of the most relevant developments in cyber security, based exclusively on open sources, with a view to inform political leadership and senior management in its constituency. Additional information on any item in this Brief can be provided upon request. Cyber Briefs are TLP:WHITE.
JVN / Japan campaign / regional advisory intelligence — 1
JVNDB-2014-000097
Dominion KX2-101 vulnerable to denial-of-service (DoS)
Published 2014-08-12T14:03:58+09:00
epiq_api : raritan

Public sources document default credentials associated with this vendor or product. No login attempt was performed.

Source: scantide_default_credentials
References

Oracle

Vendor:
unknown
18 upcoming vendor advisories 39 campaign/advisory records
FBI / IC3 campaign / regional advisory intelligence — 4
25091f9b0f59b31c2bd98141
Iranian State Actors Conduct Cyber Operations Against the Government of Albania
32fea06933ed880e2baf94a5
Cyber Criminals Increasingly Exploit Vulnerabilities in Decentralized Finance Platforms to Obtain Cryptocurrency, Causing Investors to Lose Money
c1e6dfe7f5ede874b7f6049b
2022 Top Routinely Exploited Vulnerabilities
fa89754768997e9e243a4438
North Korea Cyber Group Conducts Global Espionage Campaign to Advance Regime's Military and Nuclear Programs
CERT-EU campaign / regional advisory intelligence — 20
05bd242fd3f8859308bab2f8
2013-053: Oracle Java SE Critical Patch Update - June 2013 Friday, June 21, 2013 02:59:00 PM CEST The Oracle Java SE Critical Patch Update [1] for June 2013 were released on.
0b03f2f7f8921c77fce46a8f
2014-169: NEW SSLv3 Padding Oracle On Downgraded Legacy Encryption attack Thursday, November 20, 2014 10:09:00 AM CET The SSL protocol 3.0, as used in OpenSSL and other products, uses non-deterministic CBC padding, which makes it easier for man-in-the-middle attackers to obtain clear text data via a padding-oracle attack, aka the "POODLE" issue.
101e1f0f11d0be1353a3e8f6
Cyber Brief 25-12 - November 2025 Tuesday, December 02, 2025 04:00:00 PM CET Cyber Briefs are monthly executive reports that aim to present an overview of the most relevant developments in cyber security, based exclusively on open sources, with a view to inform political leadership and senior management in its constituency. Additional information on any item in this Brief can be provided upon request. Cyber Briefs are TLP:CLEAR.
1424ba9a397110ec1688ac22
2012-0073: Oracle Java SE Critical Patch Update Advisory - June 2012 Wednesday, June 13, 2012 04:52:00 PM CEST A Critical Patch Update is a collection of patches for multiple security vulnerabilities. The Critical Patch Update for Java SE also includes non-security fixes.
164e9b5c225d1223c305e30c
Cyber Brief 25-11 - October 2025 Saturday, November 01, 2025 04:00:00 PM CET Cyber Briefs are monthly executive reports that aim to present an overview of the most relevant developments in cyber security, based exclusively on open sources, with a view to inform political leadership and senior management in its constituency. Additional information on any item in this Brief can be provided upon request. Cyber Briefs are TLP:CLEAR.
1b0e1f9069dff7138fba17b4
2020-054: Critical Vulnerability in Oracle WebLogic Server Tuesday, November 03, 2020 04:13:00 PM CET On the 1st of November 2020, Oracle released an out-of-band patch to address a critical vulnerability (CVSS score 9.8) that has been assigned CVE-2020-14750. According to Oracle, this bug is linked to the vulnerability CVE-2020-14882. However, Oracle did not provide any information about the relation between both of the security flaws. The CVE-2020-14750 vulnerability could allow a non-authentic
1b73dcbba2ab33095336de4b
2022-006: Critical Vulnerabilities in Multiple Oracle Products Thursday, January 20, 2022 06:24:00 PM CET On January 18th, Oracle released their quarterly Critical Patch Update advisory, a collection of patches that addresses hundreds of critical security flaws, affecting several of their products. Many of these vulnerabilities may be remotely exploited without the need for user credentials. It is therefore highly recommended to apply the security patches without delay.
1fcf21fda66910438380068c
2013
28700f0ed9d3200ac276ae2b
2012-0059: Vulnerability in the Oracle Grid Engine component of Oracle Sun Products Suite Monday, April 30, 2012 02:13:00 PM CEST Two critical vulnerabilities have been identified in the Oracle Grid Engine component of Oracle Sun Products Suite
2b8496d7d1db50e1ed8025a7
2012-0004: Remote Security Vulnerability in Oracle Sun Solaris Friday, January 20, 2012 02:16:00 PM CET Oracle Sun Solaris is prone to a remote security vulnerability. Fixes are available.
2d9da3e5556cc55032f0b42f
2021-037: Critical Vulnerabilities in Oracle WebLogic Server Thursday, July 22, 2021 04:24:00 PM CEST Within the Critical Patch Update for July 2021 addressing hundreds of vulnerabilities across multiple products, Oracle released information about critical vulnerabilities affecting WebLogic Server.
3260db19d0763137915d5a52
2022-029: UPDATE: Oracle Java SE RCE Vulnerability Thursday, April 21, 2022 02:21:00 PM CEST Oracle published a Critical Patch Update Advisory - April 2022 which is a collection of patches for multiple security vulnerabilities. This Critical Patch Update contains 520 new security patches across the product families.One of the vulnerabilities is CVE-2022-21449. It is an exploitable vulnerability which allows unauthenticated attacker with network access via multiple protocols to compromise Oracle
3d5dadd623e642eb42c811ef
2019-010: UPDATE: Oracle WebLogic 0-day Vulnerability Friday, April 26, 2019 05:00:00 PM CEST A highly critical, zero-day vulnerability in Oracle WebLogic server was disclosed. Some attackers might have already started exploiting it in the wild. The vulnerability potentially allows attackers to remotely execute arbitrary commands. Oracle has issued an out-of-band security update to address this vulnerability.
3d84eec3454c9182bb0378cb
2013-0012: UPDATED - Oracle Java 0-day Vulnerability Exploited in the Wild Thursday, January 17, 2013 10:26:00 AM CET This Security Alert addresses security issues CVE-2013-0422 (US-CERT Alert TA13-010A - Oracle Java 7 Security Manager Bypass Vulnerability) and another vulnerability possibly related to "permissions of certain Java classes," as exploited in the wild in January 2013, and as demonstrated by Blackhole and Nuclear Pack, affecting Java running in web browsers.
3fc2df2c6c621004c626c231
2012-0124: Oracle Critical Patch Update - October 2012 Wednesday, October 17, 2012 03:13:00 PM CEST The Critical Patch Update for October 2012 [2] and The Oracle Java SE Critical Patch Update [3] for October 2012 were released. Oracle strongly recommends applying the patches as soon as possible. Please note that Sun products are included in this Critical Patch Update.
427c825a3f797f5dd34544e0
2020-053: Critical Vulnerability in Oracle WebLogic Server Friday, October 30, 2020 05:38:00 PM CET In October, within the monthly Critical Patch Update Advisory addressing hundreds of vulnerabilities, Oracle released an update about a critical vulnerability affecting WebLogic Server. This vulnerability may allow unauthenticated attackers with network access via HTTP to achieve total compromise and takeover of vulnerable Oracle WebLogic Servers. This bug has been assigned CVE-2020-14882 and has
4b789a247e4930d4850ae736
2020-055: Critical Vulnerability in the Solaris PAM Library Thursday, November 05, 2020 02:32:00 PM CET Within its monthly Critical Patch Update Advisory, Oracle released patch for a critical vulnerability affecting Solaris Pluggable Authentication Module (PAM).FireEye discovered during an investigation traces of exploitation of this vulnerability since 2018. Moreover, FireEye associated the vulnerability with Oracle Solaris SSHD Remote Root Exploit identified on black-market for sale. This vuln
4d2e7c21608430e5950b4683
2013-0058: Oracle Critical Patch Update Advisory Friday, August 09, 2013 01:01:00 PM CEST The Oracle Critical Patch Update for July 2013 [1] were released. Oracle strongly recommends applying the patches as soon as possible.
4d5a58376a2df4824e4643b6
2012-0079: Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Tuesday, July 03, 2012 02:47:00 PM CEST Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 update 4 and earlier allows remote attackers to affect confidentiality and integrity via unknown vectors related to Libraries
57f4da2583be950a807f16f7
2014-043: Oracle Critical Patch Update Advisory Thursday, May 08, 2014 04:31:00 PM CEST The Oracle Critical Patch Update for April 2014 [1] were released.
JVN / Japan campaign / regional advisory intelligence — 15
JVNDB-2005-000727
mod_imap cross-site scripting vulnerability
Published 2008-05-21T00:00:00+09:00
JVNDB-2007-000819
Cross-site scripting vulnerability in Apache HTTP Server "mod_imap" and "mod_imagemap"
Published 2008-05-21T00:00:00+09:00
JVNDB-2008-000040
Directory traversal vulnerability in WebLogic Server and WebLogic Express plug-ins
Published 2008-07-24T14:22:29+09:00
JVNDB-2009-000007
Oracle WebLogic Server vulnerable to cross-site scripting
Published 2009-01-20T16:45:07+09:00
JVNDB-2009-002069
Oracle iPlanet Web Server information disclosure vulnerability
Published 2011-07-25T18:06:11+09:00
JVNDB-2010-000004
Oracle Application Server vulnerable to cross-site scripting
Published 2010-01-14T21:24:17+09:00
JVNDB-2010-000042
Cross-site Request Forgery Vulnerability in Oracle iPlanet Web Server
Published 2010-10-18T19:37:08+09:00
JVNDB-2010-000054
Flash Player access restriction bypass vulnerability
Published 2010-11-09T19:59:22+09:00
JVNDB-2012-000007
Oracle WebLogic Server vulnerable to cross-site scripting
Published 2012-01-20T15:37:30+09:00
JVNDB-2013-000070
Oracle Outside In vulnerable to buffer overflow
Published 2013-07-17T13:45:49+09:00
JVNDB-2013-000071
Oracle Outside In vulnerable to denial-of-service (DoS)
Published 2013-07-17T13:56:43+09:00
JVNDB-2013-003391
Oracle Enterprise Manager vulnerable to cross-site scripting
Published 2013-07-22T15:00:03+09:00
JVNDB-2013-003469
Apache Struts vulnerable to remote command execution
Published 2013-09-06T14:12:18+09:00
JVNDB-2024-000014
Oracle WebLogic Server vulnerable to HTTP header injection
Published 2024-01-24T13:53:09+09:00
JVNDB-2020-000047
JavaFX WebEngine does not properly restrict Java method execution
Published 2020-07-28T15:47:48+09:00
Upcoming ZDI vendor advisories — 18

Vendor-level advance notice: ZDI has not yet disclosed which product is affected. These entries are shown because this credential record matches the vendor; they are not findings against this product or model.

ZDI-CAN-29370 CVSS 7.8
Vendor contacted: 2026-03-31 Planned disclosure: 2026-07-29 Researcher: Dvir Gozlan
Affected product: Not yet disclosed · Open ZDI Upcoming
ZDI-CAN-29543 CVSS 7.8
Vendor contacted: 2026-04-08 Planned disclosure: 2026-08-06 Researcher: Mat Powell of TrendAI Zero Day Initiative
Affected product: Not yet disclosed · Open ZDI Upcoming
ZDI-CAN-29542 CVSS 7.8
Vendor contacted: 2026-04-08 Planned disclosure: 2026-08-06 Researcher: Mat Powell of TrendAI Zero Day Initiative
Affected product: Not yet disclosed · Open ZDI Upcoming
ZDI-CAN-29541 CVSS 7.8
Vendor contacted: 2026-04-08 Planned disclosure: 2026-08-06 Researcher: Mat Powell of TrendAI Zero Day Initiative
Affected product: Not yet disclosed · Open ZDI Upcoming
ZDI-CAN-31766 CVSS 7.8
Vendor contacted: 2026-06-10 Planned disclosure: 2026-10-08 Researcher: Mat Powell of TrendAI Zero Day Initiative
Affected product: Not yet disclosed · Open ZDI Upcoming
ZDI-CAN-31765 CVSS 7.8
Vendor contacted: 2026-06-10 Planned disclosure: 2026-10-08 Researcher: Mat Powell of TrendAI Zero Day Initiative
Affected product: Not yet disclosed · Open ZDI Upcoming
ZDI-CAN-31767 CVSS 7.8
Vendor contacted: 2026-06-10 Planned disclosure: 2026-10-08 Researcher: Mat Powell of TrendAI Zero Day Initiative
Affected product: Not yet disclosed · Open ZDI Upcoming
ZDI-CAN-31777 CVSS 7.8
Vendor contacted: 2026-06-10 Planned disclosure: 2026-10-08 Researcher: Mat Powell of TrendAI Zero Day Initiative
Affected product: Not yet disclosed · Open ZDI Upcoming
ZDI-CAN-31842 CVSS 9.3
Vendor contacted: 2026-06-16 Planned disclosure: 2026-10-14 Researcher: Lucas Miller of TrendAI Research
Affected product: Not yet disclosed · Open ZDI Upcoming
ZDI-CAN-32013 CVSS 9.9
Vendor contacted: 2026-06-23 Planned disclosure: 2026-10-21 Researcher: Bobby Gould (@bobbygould5) of TrendAI Zero Day Initiative
Affected product: Not yet disclosed · Open ZDI Upcoming
ZDI-CAN-29751 CVSS 7.5
Vendor contacted: 2026-06-25 Planned disclosure: 2026-10-23 Researcher: Team Amazone@229
Affected product: Not yet disclosed · Open ZDI Upcoming
ZDI-CAN-30083 CVSS 7.5
Vendor contacted: 2026-06-25 Planned disclosure: 2026-10-23 Researcher: crixer(@pwning_me)
Affected product: Not yet disclosed · Open ZDI Upcoming
ZDI-CAN-32169 CVSS 7.8
Vendor contacted: 2026-06-30 Planned disclosure: 2026-10-28 Researcher: Mat Powell of TrendAI Zero Day Initiative
Affected product: Not yet disclosed · Open ZDI Upcoming
ZDI-CAN-31121 CVSS 7.5
Vendor contacted: 2026-07-07 Planned disclosure: 2026-11-04 Researcher: Xiaobye(@xiaobye_tw) of DEVCORE Research Team
Affected product: Not yet disclosed · Open ZDI Upcoming
ZDI-CAN-30184 CVSS 7.5
Vendor contacted: 2026-07-10 Planned disclosure: 2026-11-07 Researcher: Phan Vinh Khang of Viettel Cyber Security
Affected product: Not yet disclosed · Open ZDI Upcoming
ZDI-CAN-29835 CVSS 6.1
Vendor contacted: 2026-07-10 Planned disclosure: 2026-11-07 Researcher: Xiaobye(@xiaobye_tw) of DEVCORE Research Team
Affected product: Not yet disclosed · Open ZDI Upcoming
ZDI-CAN-31532 CVSS 6.1
Vendor contacted: 2026-07-24 Planned disclosure: 2026-11-21 Researcher: vmpr0be
Affected product: Not yet disclosed · Open ZDI Upcoming
ZDI-CAN-31625 CVSS 5.3
Vendor contacted: 2026-07-24 Planned disclosure: 2026-11-21 Researcher: vmpr0be
Affected product: Not yet disclosed · Open ZDI Upcoming
OLAPDBA : OLAPDBA

Public sources document default credentials associated with this vendor or product. No login attempt was performed.

Source: scantide_default_credentials
References

Teletronics

Vendor:
unknown
admin : [blank]

Public sources document default credentials associated with this vendor or product. No login attempt was performed.

Source: scantide_default_credentials

WebLogic Process Integrator

Vendor:
· Model: WebLogic Process Integrator
unknown
18 upcoming vendor advisories 55 campaign/advisory records
FBI / IC3 campaign / regional advisory intelligence — 20
c1e6dfe7f5ede874b7f6049b
2022 Top Routinely Exploited Vulnerabilities
25091f9b0f59b31c2bd98141
Iranian State Actors Conduct Cyber Operations Against the Government of Albania
fa89754768997e9e243a4438
North Korea Cyber Group Conducts Global Espionage Campaign to Advance Regime's Military and Nuclear Programs
32fea06933ed880e2baf94a5
Cyber Criminals Increasingly Exploit Vulnerabilities in Decentralized Finance Platforms to Obtain Cryptocurrency, Causing Investors to Lose Money
02c564e5d11e235eccef00f3
New Sandworm malware Cyclops Blink replaces VPNFilter
034b6dd4edcdf314784d621e
Unpatched and Outdated Medical Devices Provide Cyber Attack Opportunities
0656fd99c93dfd5a6bca805c
Just So You Know: Ransomware Disruptions during Voting Periods Will Not Impact the Security and Resiliency of Vote Casting or Counting
0698638c72fa1363ede20ec4
2021 Trends Show Increased Globalized Threat of Ransomware
0a2ed3f904e1b539478b556c
APT40 Advisory: PRC MSS tradecraft in action
0dc584846605837f1c8a21d5
Just So You Know: False Claims of Hacked Voter Information Likely Intended to Sow Distrust of U.S. Elections — FBI An official website of the United States government. Here's how you know Official websites use .gov A .gov website belongs to an official government organization in the United States. Secure .gov websites use HTTPS A lock ( ) or https:// means you've safely connected to the .gov websi
11c95addfb97b7069dc5873a
Compromise of Microsoft Exchange Server
11f725160c85af3ba01849cc
People's Republic of China State-Sponsored Cyber Actor Living off the Land to Evade Detection
1293a5f384189b121e72eaea
Suspected PRC Cyber Actors Continue to Globally Exploit Barracuda ESG Zero-Day Vulnerability
1425b84a538a19f525596083
Tech Support Scam
1499297aad75b4e344422d39
#StopRansomware: Royal Ransomware
18b1a5dc6a6d45c83187f7ca
Tactics, Techniques, and Procedures of Indicted State-Sponsored Russian Cyber Actors Targeting the Energy Sector
18e9b4a33f64684443f98e6c
Malicious Actors Exploit CVE-2023-27350 in PaperCut MF and NG
1a89e7cf2bfa6441030da3d1
Incident Response Guide: Water and Wastewater Sector
1cabacddc320508fb266e21c
Cyber Actors Target K-12 Distance Learning Education to Cause Disruptions and Steal Data
1efa1000eaeeb618a2350cd3
Threats Associated with the Israel-HAMAS Conflict
CERT-EU campaign / regional advisory intelligence — 20
aa9b2491c54a8ce983f371e9
2021-002: Critical Vulnerabilities in Multiple Oracle Products Wednesday, January 20, 2021 03:04:00 PM CET Oracle has published an advisory about hundreds of critical vulnerabilities are affecting several of its products. Many of the vulnerabilities can be remotely exploited without authentication and without user interaction. Expedient patching of the affected products is highly recommended.
101e1f0f11d0be1353a3e8f6
Cyber Brief 25-12 - November 2025 Tuesday, December 02, 2025 04:00:00 PM CET Cyber Briefs are monthly executive reports that aim to present an overview of the most relevant developments in cyber security, based exclusively on open sources, with a view to inform political leadership and senior management in its constituency. Additional information on any item in this Brief can be provided upon request. Cyber Briefs are TLP:CLEAR.
1b0e1f9069dff7138fba17b4
2020-054: Critical Vulnerability in Oracle WebLogic Server Tuesday, November 03, 2020 04:13:00 PM CET On the 1st of November 2020, Oracle released an out-of-band patch to address a critical vulnerability (CVSS score 9.8) that has been assigned CVE-2020-14750. According to Oracle, this bug is linked to the vulnerability CVE-2020-14882. However, Oracle did not provide any information about the relation between both of the security flaws. The CVE-2020-14750 vulnerability could allow a non-authentic
2d9da3e5556cc55032f0b42f
2021-037: Critical Vulnerabilities in Oracle WebLogic Server Thursday, July 22, 2021 04:24:00 PM CEST Within the Critical Patch Update for July 2021 addressing hundreds of vulnerabilities across multiple products, Oracle released information about critical vulnerabilities affecting WebLogic Server.
3d5dadd623e642eb42c811ef
2019-010: UPDATE: Oracle WebLogic 0-day Vulnerability Friday, April 26, 2019 05:00:00 PM CEST A highly critical, zero-day vulnerability in Oracle WebLogic server was disclosed. Some attackers might have already started exploiting it in the wild. The vulnerability potentially allows attackers to remotely execute arbitrary commands. Oracle has issued an out-of-band security update to address this vulnerability.
427c825a3f797f5dd34544e0
2020-053: Critical Vulnerability in Oracle WebLogic Server Friday, October 30, 2020 05:38:00 PM CET In October, within the monthly Critical Patch Update Advisory addressing hundreds of vulnerabilities, Oracle released an update about a critical vulnerability affecting WebLogic Server. This vulnerability may allow unauthenticated attackers with network access via HTTP to achieve total compromise and takeover of vulnerable Oracle WebLogic Servers. This bug has been assigned CVE-2020-14882 and has
65091666d8e6bfcaa5d1f9af
2019
65c0f9d2753fd4f42c81979a
2022
a0018c749f30221cebfa3a3c
2020
b26f28de9b641cad7d4df2cb
2020-004: Critical Vulnerabilities in Multiple Oracle Products Wednesday, January 15, 2020 12:57:00 PM CET Oracle has published an advisory about hundreds of critical vulnerabilities that are affecting several of its products. Many of the vulnerabilities can be remotely exploited without authentication and without user interaction. Expedient patching of the affected products is highly recommended.
d379c4be4846d1ec6b3611c5
2012-0013: Denial of Service Vulnerability in Oracle WebLogic Server, Application Server (OC4J) and iPlanet Web Server Thursday, February 02, 2012 03:15:00 PM CET Oracle has released a security advisory about a denial of service vulnerability in Oracle WebLogic Server, Oracle Application Server (OC4J) and Oracle iPlanet Web Server due to hashing collisions. No authentication is required to exploit this vulnerability, so it may be exploited over a network without the need for a username and passw
d3eb32fb0c1ced517261461f
2018
d5e743aa7be8c37f1b674811
2018-018: WebLogic Vulnerability Exploited In The Wild Thursday, July 26, 2018 05:00:00 PM CEST Recently Oracle released patches for vulnerability CVE-2018-2893. This vulnerability allows an unauthenticated attacker to compromise Oracle WebLogic Server. Exploits were published on GitHub and on other websites after the announcement of the security updates. There were reported attacks against vulnerable instances.
f1ddec25aa9b68ee9d88620f
2020-026: Critical Oracle WebLogic Server Vulnerability Exploited Tuesday, May 12, 2020 06:08:00 PM CEST In April, within the monthly Critical Patch Update Advisory addressing hundreds of vulnerabilities, Oracle released an update about a critical vulnerability affecting WebLogic Server. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Oracle WebLogic. Authentication is not required to exploit this vulnerability. This bug, assigned with CVE-2020-2
05bd242fd3f8859308bab2f8
2013-053: Oracle Java SE Critical Patch Update - June 2013 Friday, June 21, 2013 02:59:00 PM CEST The Oracle Java SE Critical Patch Update [1] for June 2013 were released on.
0b03f2f7f8921c77fce46a8f
2014-169: NEW SSLv3 Padding Oracle On Downgraded Legacy Encryption attack Thursday, November 20, 2014 10:09:00 AM CET The SSL protocol 3.0, as used in OpenSSL and other products, uses non-deterministic CBC padding, which makes it easier for man-in-the-middle attackers to obtain clear text data via a padding-oracle attack, aka the "POODLE" issue.
1424ba9a397110ec1688ac22
2012-0073: Oracle Java SE Critical Patch Update Advisory - June 2012 Wednesday, June 13, 2012 04:52:00 PM CEST A Critical Patch Update is a collection of patches for multiple security vulnerabilities. The Critical Patch Update for Java SE also includes non-security fixes.
164e9b5c225d1223c305e30c
Cyber Brief 25-11 - October 2025 Saturday, November 01, 2025 04:00:00 PM CET Cyber Briefs are monthly executive reports that aim to present an overview of the most relevant developments in cyber security, based exclusively on open sources, with a view to inform political leadership and senior management in its constituency. Additional information on any item in this Brief can be provided upon request. Cyber Briefs are TLP:CLEAR.
1b73dcbba2ab33095336de4b
2022-006: Critical Vulnerabilities in Multiple Oracle Products Thursday, January 20, 2022 06:24:00 PM CET On January 18th, Oracle released their quarterly Critical Patch Update advisory, a collection of patches that addresses hundreds of critical security flaws, affecting several of their products. Many of these vulnerabilities may be remotely exploited without the need for user credentials. It is therefore highly recommended to apply the security patches without delay.
1fcf21fda66910438380068c
2013
JVN / Japan campaign / regional advisory intelligence — 15
JVNDB-2005-000727
mod_imap cross-site scripting vulnerability
Published 2008-05-21T00:00:00+09:00
JVNDB-2007-000819
Cross-site scripting vulnerability in Apache HTTP Server "mod_imap" and "mod_imagemap"
Published 2008-05-21T00:00:00+09:00
JVNDB-2008-000040
Directory traversal vulnerability in WebLogic Server and WebLogic Express plug-ins
Published 2008-07-24T14:22:29+09:00
JVNDB-2009-000007
Oracle WebLogic Server vulnerable to cross-site scripting
Published 2009-01-20T16:45:07+09:00
JVNDB-2009-002069
Oracle iPlanet Web Server information disclosure vulnerability
Published 2011-07-25T18:06:11+09:00
JVNDB-2010-000004
Oracle Application Server vulnerable to cross-site scripting
Published 2010-01-14T21:24:17+09:00
JVNDB-2010-000042
Cross-site Request Forgery Vulnerability in Oracle iPlanet Web Server
Published 2010-10-18T19:37:08+09:00
JVNDB-2010-000054
Flash Player access restriction bypass vulnerability
Published 2010-11-09T19:59:22+09:00
JVNDB-2012-000007
Oracle WebLogic Server vulnerable to cross-site scripting
Published 2012-01-20T15:37:30+09:00
JVNDB-2013-000070
Oracle Outside In vulnerable to buffer overflow
Published 2013-07-17T13:45:49+09:00
JVNDB-2013-000071
Oracle Outside In vulnerable to denial-of-service (DoS)
Published 2013-07-17T13:56:43+09:00
JVNDB-2013-003391
Oracle Enterprise Manager vulnerable to cross-site scripting
Published 2013-07-22T15:00:03+09:00
JVNDB-2013-003469
Apache Struts vulnerable to remote command execution
Published 2013-09-06T14:12:18+09:00
JVNDB-2024-000014
Oracle WebLogic Server vulnerable to HTTP header injection
Published 2024-01-24T13:53:09+09:00
JVNDB-2020-000047
JavaFX WebEngine does not properly restrict Java method execution
Published 2020-07-28T15:47:48+09:00
Upcoming ZDI vendor advisories — 18

Vendor-level advance notice: ZDI has not yet disclosed which product is affected. These entries are shown because this credential record matches the vendor; they are not findings against this product or model.

ZDI-CAN-29370 CVSS 7.8
Vendor contacted: 2026-03-31 Planned disclosure: 2026-07-29 Researcher: Dvir Gozlan
Affected product: Not yet disclosed · Open ZDI Upcoming
ZDI-CAN-29543 CVSS 7.8
Vendor contacted: 2026-04-08 Planned disclosure: 2026-08-06 Researcher: Mat Powell of TrendAI Zero Day Initiative
Affected product: Not yet disclosed · Open ZDI Upcoming
ZDI-CAN-29542 CVSS 7.8
Vendor contacted: 2026-04-08 Planned disclosure: 2026-08-06 Researcher: Mat Powell of TrendAI Zero Day Initiative
Affected product: Not yet disclosed · Open ZDI Upcoming
ZDI-CAN-29541 CVSS 7.8
Vendor contacted: 2026-04-08 Planned disclosure: 2026-08-06 Researcher: Mat Powell of TrendAI Zero Day Initiative
Affected product: Not yet disclosed · Open ZDI Upcoming
ZDI-CAN-31766 CVSS 7.8
Vendor contacted: 2026-06-10 Planned disclosure: 2026-10-08 Researcher: Mat Powell of TrendAI Zero Day Initiative
Affected product: Not yet disclosed · Open ZDI Upcoming
ZDI-CAN-31765 CVSS 7.8
Vendor contacted: 2026-06-10 Planned disclosure: 2026-10-08 Researcher: Mat Powell of TrendAI Zero Day Initiative
Affected product: Not yet disclosed · Open ZDI Upcoming
ZDI-CAN-31767 CVSS 7.8
Vendor contacted: 2026-06-10 Planned disclosure: 2026-10-08 Researcher: Mat Powell of TrendAI Zero Day Initiative
Affected product: Not yet disclosed · Open ZDI Upcoming
ZDI-CAN-31777 CVSS 7.8
Vendor contacted: 2026-06-10 Planned disclosure: 2026-10-08 Researcher: Mat Powell of TrendAI Zero Day Initiative
Affected product: Not yet disclosed · Open ZDI Upcoming
ZDI-CAN-31842 CVSS 9.3
Vendor contacted: 2026-06-16 Planned disclosure: 2026-10-14 Researcher: Lucas Miller of TrendAI Research
Affected product: Not yet disclosed · Open ZDI Upcoming
ZDI-CAN-32013 CVSS 9.9
Vendor contacted: 2026-06-23 Planned disclosure: 2026-10-21 Researcher: Bobby Gould (@bobbygould5) of TrendAI Zero Day Initiative
Affected product: Not yet disclosed · Open ZDI Upcoming
ZDI-CAN-29751 CVSS 7.5
Vendor contacted: 2026-06-25 Planned disclosure: 2026-10-23 Researcher: Team Amazone@229
Affected product: Not yet disclosed · Open ZDI Upcoming
ZDI-CAN-30083 CVSS 7.5
Vendor contacted: 2026-06-25 Planned disclosure: 2026-10-23 Researcher: crixer(@pwning_me)
Affected product: Not yet disclosed · Open ZDI Upcoming
ZDI-CAN-32169 CVSS 7.8
Vendor contacted: 2026-06-30 Planned disclosure: 2026-10-28 Researcher: Mat Powell of TrendAI Zero Day Initiative
Affected product: Not yet disclosed · Open ZDI Upcoming
ZDI-CAN-31121 CVSS 7.5
Vendor contacted: 2026-07-07 Planned disclosure: 2026-11-04 Researcher: Xiaobye(@xiaobye_tw) of DEVCORE Research Team
Affected product: Not yet disclosed · Open ZDI Upcoming
ZDI-CAN-30184 CVSS 7.5
Vendor contacted: 2026-07-10 Planned disclosure: 2026-11-07 Researcher: Phan Vinh Khang of Viettel Cyber Security
Affected product: Not yet disclosed · Open ZDI Upcoming
ZDI-CAN-29835 CVSS 6.1
Vendor contacted: 2026-07-10 Planned disclosure: 2026-11-07 Researcher: Xiaobye(@xiaobye_tw) of DEVCORE Research Team
Affected product: Not yet disclosed · Open ZDI Upcoming
ZDI-CAN-31532 CVSS 6.1
Vendor contacted: 2026-07-24 Planned disclosure: 2026-11-21 Researcher: vmpr0be
Affected product: Not yet disclosed · Open ZDI Upcoming
ZDI-CAN-31625 CVSS 5.3
Vendor contacted: 2026-07-24 Planned disclosure: 2026-11-21 Researcher: vmpr0be
Affected product: Not yet disclosed · Open ZDI Upcoming
joe : password

Public sources document default credentials associated with this vendor or product. No login attempt was performed.

Source: scantide_default_credentials

DDW 366

Vendor:
· Model: DDW 366
unknown
user : user

Public sources document default credentials associated with this vendor or product. No login attempt was performed.

Source: scantide_default_credentials

Arris

Vendor:
unknown
admin : [blank]

Public sources document default credentials associated with this vendor or product. No login attempt was performed.

Source: scantide_default_credentials

drupal.org

Vendor:
unknown
admin : [blank]

Public sources document default credentials associated with this vendor or product. No login attempt was performed.

Source: scantide_default_credentials

Unspecified device or product

Vendor:
· Model: Unspecified device or product
unknown
61 campaign/advisory records
FBI / IC3 campaign / regional advisory intelligence — 20
590b43d2bf56104d53f7eb63
#StopRansomware: Ransomware Attacks on Critical Infrastructure Fund DPRK Malicious Cyber Activities
18e9b4a33f64684443f98e6c
Malicious Actors Exploit CVE-2023-27350 in PaperCut MF and NG
FBI_IC3-260603.pdf
Safeguarding China’s military intelligence services use OUR SECRETS Western online job platforms to lure Five Eyes nationals with access to sensitive information THE THREAT Who is at RISK? China’s military intelligence services are using Ch
00ee01eaa94d894ac31549d1
Senior U.S. Officials Continue To Be Impersonated in Malicious Messaging Campaign — FBI An official website of the United States government. Here's how you know Official websites use .gov A .gov website belongs to an official government organization in the United States. Secure .gov websites use HTTPS A lock ( ) or https:// means you've safely connected to the .gov website. Share sensitive informa
02c564e5d11e235eccef00f3
New Sandworm malware Cyclops Blink replaces VPNFilter
034b6dd4edcdf314784d621e
Unpatched and Outdated Medical Devices Provide Cyber Attack Opportunities
0698638c72fa1363ede20ec4
2021 Trends Show Increased Globalized Threat of Ransomware
079a3cda352373ebc1ad2e38
Sexual Exploitation Actors Stealing and Leaking Explicit Content
0e29017b2b1f766d58fd49be
Malicious Cyber Actors Targeting Water and Wastewater Sector Internet- Facing Programmable Logic Controllers, Causing Operational Disruptions — FBI An official website of the United States government. Here's how you know Official websites use .gov A .gov website belongs to an official government organization in the United States. Secure .gov websites use HTTPS A lock ( ) or https:// means you've s
1293a5f384189b121e72eaea
Suspected PRC Cyber Actors Continue to Globally Exploit Barracuda ESG Zero-Day Vulnerability
1499297aad75b4e344422d39
#StopRansomware: Royal Ransomware
18b1a5dc6a6d45c83187f7ca
Tactics, Techniques, and Procedures of Indicted State-Sponsored Russian Cyber Actors Targeting the Energy Sector
1a89e7cf2bfa6441030da3d1
Incident Response Guide: Water and Wastewater Sector
1e1e19419dbe954c101e3fe4
Conti Ransomware Attacks Impact Healthcare and First Responder Networks
1fab757041bfd1ced82bd35c
Cyber Criminals Targeting Healthcare Payment Processors, Costing Victims Millions in Losses
20fccf4dc914e7de91594312
Karakurt Data Extortion Group
211475863b97d3021882ed29
Guidance on the 911 S5 Residential Proxy Service
221b0868c40f7ad490c24d12
Russian Foreign Intelligence Service (SVR) Cyber Operations: Trends and Best Practices for Network Defenders
23ecec0c3c508513e5d9a1bb
Russian State-Sponsored Cyber Actors Gain Network Access by Exploiting Default Multifactor Authentication Protocols and "PrintNightmare" Vulnerability
24eae392c7e3a25cf0cb8d60
Ransomware Attacks Straining Local US Governments and Public Services
CERT-EU campaign / regional advisory intelligence — 20
b81b121dddb0c27a5310bf42
Cyber Security Brief 23-03 - February 2023 Wednesday, March 01, 2023 03:00:00 PM CET Cyber Security Briefs are monthly executive reports that aim to present an overview of the most relevant developments in cyber security, based exclusively on open sources, with a view to inform political leadership and senior management in its constituency. Additional information on any item in this Brief can be provided upon request. Cyber Security Briefs are TLP:CLEAR.
18bfae0e0c79e8b78830cee5
2022-067: Critical WhatsApp Vulnerabilities Friday, September 30, 2022 02:12:00 PM CEST WhatsApp has patched two remote code execution vulnerabilities in its September update. These could have allowed an attacker to remotely access a device and execute commands. The vulnerabilities were discovered by WhatsApp internal security team and there are no indications that these have already been exploited.
1fcf21fda66910438380068c
2013
3149ef4d675627192800b4d0
Cyber Brief 26-04 - March 2026 Wednesday, April 01, 2026 05:00:00 PM CEST Cyber Briefs are monthly executive reports that aim to present an overview of the most relevant developments in cyber security, based exclusively on open sources, with a view to inform political leadership and senior management in its constituency. Additional information on any item in this Brief can be provided upon request. Cyber Briefs are TLP:CLEAR.
44f727a65fb55938c1865dfb
2022-071: Junos OS: Multiple Vulnerabilities in J-Web Monday, October 17, 2022 01:50:00 AM CEST Multiple vulnerabilities have been found in the J-Web component of Juniper Networks Junos OS. One or more of these issues could lead to unauthorized local file access, cross-site scripting attacks, path injection and traversal, or local file inclusion.
9c97832c4deff24c44466de4
Cyber Security Brief 23-08 - July 2023 Tuesday, August 01, 2023 08:30:00 PM CEST Cyber Security Briefs are monthly executive reports that aim to present an overview of the most relevant developments in cyber security, based exclusively on open sources, with a view to inform political leadership and senior management in its constituency. Additional information on any item in this Brief can be provided upon request. Cyber Security Briefs are TLP:CLEAR.
b3384778dc49dc28ed930803
Cyber Security Brief - October 2022 Thursday, November 03, 2022 10:50:00 AM CET Cyber Security Briefs are monthly executive reports that aim to present an overview of the most relevant developments in cyber security, based exclusively on open sources, with a view to inform political leadership and senior management in its constituency. Additional information on any item in this Brief can be provided upon request. Cyber Security Briefs are TLP:WHITE.
de704e1e5302955ec55869fe
Cyber Brief 24-10 - September 2024 Tuesday, October 01, 2024 06:00:00 PM CEST Cyber Briefs are monthly executive reports that aim to present an overview of the most relevant developments in cyber security, based exclusively on open sources, with a view to inform political leadership and senior management in its constituency. Additional information on any item in this Brief can be provided upon request. Cyber Security Briefs are TLP:CLEAR.
03f275e81a7d188dbbd18cbc
2018-011: Cisco Products Multiple Vulnerabilities Thursday, April 19, 2018 04:36:00 PM CEST On the 17th and 18th of April 2018, Cisco has released several updates to address vulnerabilities affecting multiple products in which a remote attacker can exploit these vulnerabilities to trigger cross site scripting, denial of service, remote code execution, security restriction bypass and sensitive information disclosure on the targeted system.
1223ca5566f4db106d0b5dac
2024-031: High Severity Vulnerabilities in Cisco Products Friday, March 29, 2024 11:49:02 AM CET On March 27, 2024, Cisco released security updates for fourteen (14) vulnerabilities affecting IOS, IOS XE and Cisco Access Point software. Six (6) high severity vulnerabilities with a CVSS score of 8.6, could allow an unauthenticated, remote attacker to cause denial of service on an affected device.
164e9b5c225d1223c305e30c
Cyber Brief 25-11 - October 2025 Saturday, November 01, 2025 04:00:00 PM CET Cyber Briefs are monthly executive reports that aim to present an overview of the most relevant developments in cyber security, based exclusively on open sources, with a view to inform political leadership and senior management in its constituency. Additional information on any item in this Brief can be provided upon request. Cyber Briefs are TLP:CLEAR.
1e750323f48817bd0a0db67d
2017-023: UPDATE RSA Key Generation Prone to Factorization Attack Wednesday, October 18, 2017 12:17:00 PM CEST A vulnerability (CVE-2017-15361) in the procedure of RSA key generation used by a software library allows a practical factorization attack. As a result it is possible to compute the private part of an RSA key based only on its public part. The vulnerable library is used in cryptographic smartcards, security tokens, and other secure hardware chips manufactured by Infineon Technologies AG
284e39279deebf46bdc2edd0
2023-091: High Vulnerabilities in Citrix Hypervisor Monday, November 20, 2023 11:42:36 AM CET On November 15, 2023, Citrix issued an advisory regarding two vulnerabilities affecting Citrix Hypervisor 8.2 CU1 LTSR that could allow malicious code in a guest VM to compromise the host.
2c030c668a85d98f3d57ac9e
2021-012: Critical Vulnerabilities in Cisco Products Thursday, February 25, 2021 03:01:00 PM CET On 24th of February 2021, Cisco released several security updates to address security vulnerabilities including three critical ones: an authentication bypass (CVE-2021-1388), an unauthenticated arbitrary file actions (CVE-2021-1361), and an unauthorised access (CVE-2021-1393).
306b20e791e762e784f9a514
2021-074: CISCO Critical Vulnerability Saturday, December 18, 2021 04:05:00 PM CET On December 16th, CISCO updated its security advisory related to CVE-2021-44228 affecting many of its products. While this CVE affects the Java logging library log4j, all products using this library are vulnerable to at least Unauthenticated Remote Code Execution.
37e2b0b3f3643adf445a9c1b
2020-043: Critical Vulnerabilities in Cisco Products Thursday, September 03, 2020 01:35:00 PM CEST On 29th of August and on 2nd of September, Cisco released several security advisories, updates, and workarounds to address security vulnerabilities including five high severity vulnerabilities, and one critical:* CVE-2020-3495 - Arbitrary Code Execution - CVSS score 9.9 (critical)* CVE-2020-3566 - Memory Exhaustion - CVSS score 8.6 (high)* CVE-2020-3530 - Authenticated User Privilege Escalation - C
39779f9590d9c96f1b1ed883
2024-113: Critical 0-day Vulnerability in Fortinet FortiManager Thursday, October 24, 2024 10:56:10 AM CEST On October 23, 2024, Fortinet released a security advisory addressing a critical 0-day vulnerability in its FortiManager product. If exploited, a remote unauthenticated attacker could execute arbitrary code or commands on the affected device. It is strongly recommended applying the update. When not possible, it is recommended applying the workaround. In all cases, it is recommended searchi
4d5b1acc58b1834a93099ef5
2023-004: Critical Vulnerability in Several ManageEngine Products Monday, January 30, 2023 10:15:00 AM CET On January 18th, ManageEngine released updates to several ManageEngine OnPremise products. The potentially vulnerable products use outdated versions of the open-source library Apache Santuario (XML Security for Java). Products must have enabled Single-Sign-On (SSO) using the Security Assertion Markup Language (SAML) to be vulnerable. For some products, the SSO must be active, while for othe
54392600b4e52529de876171
2021-053: Critical Vulnerabilities in Cisco Software Friday, September 24, 2021 06:24:00 PM CEST On Wednesday, September 22, 2021, Cisco Product Security Incident Response Team (PSIRT) has released 31 security advisories (3 Critical, 13 High, 15 Medium) to address multiple vulnerabilities in Cisco IOS XE software or products running with a specific configuration. At this time, the Cisco (PSIRT) is not aware of any public announcements or malicious use of the critical vulnerabilities CVE-2021-347
579a8b2540f682b380dc70a2
Cyber Brief 25-10 - September 2025 Wednesday, October 01, 2025 05:00:00 PM CEST Cyber Briefs are monthly executive reports that aim to present an overview of the most relevant developments in cyber security, based exclusively on open sources, with a view to inform political leadership and senior management in its constituency. Additional information on any item in this Brief can be provided upon request. Cyber Briefs are TLP:CLEAR.
Europol / EC3 campaign / regional advisory intelligence — 1
aea04e7a9354b6b056bbd753
Malware Has Gone Mobile. Stop.Think.Connect. to keep cybercriminals out of your mobile device | Europol You need to enable JavaScript to run this app. Loading application. Please wait.
JVN / Japan campaign / regional advisory intelligence — 20
JVNDB-2018-000124
Multiple vulnerabilities in RICOH Interactive Whiteboard
Published 2018-11-27T15:26:13+09:00
JVNDB-2024-000061
Multiple vulnerabilities in Ricoh Streamline NX PC Client
Published 2024-06-18T14:56:11+09:00
JVNDB-2025-000039
Multiple vulnerabilities in RICOH Streamline NX PC Client
Published 2025-06-13T16:09:40+09:00
JVNDB-2025-000046
SLNX Help Documentation of RICOH Streamline NX vulnerable to reflected cross-site scripting
Published 2025-06-30T15:45:51+09:00
JVNDB-2025-000077
RICOH Streamline NX vulnerable to tampering with operation history
Published 2025-09-08T13:42:15+09:00
JVNDB-2026-000003
RICOH Streamline NX vulnerable to improper authorization
Published 2026-01-09T18:17:15+09:00
JVNDB-2026-000028
Installer for Job log aggregation/analysis software RICOH Job Log Aggregation Tool may insecurely load Dynamic Link Libraries
Published 2026-02-20T12:31:59+09:00
JVNDB-2006-000617
Multiple email clients vulnerable to directory traversal due to inappropriate unicode handling
Published 2008-05-21T00:00:00+09:00
JVNDB-2019-000058
Multiple buffer overflow vulnerabilities in multiple Ricoh printers and Multifunction Printers (MFPs)
Published 2019-09-13T14:29:14+09:00
JVNDB-2019-000067
Library Information Management System LIMEDIO vulnerable to open redirect
Published 2019-10-28T15:37:11+09:00
JVNDB-2019-014031
Cross-site Request Forgery Vulnerability in RICOH printers
Published 2020-02-25T14:06:32+09:00
JVNDB-2019-014136
Information Disclosure Vulnerability in RICOH printers
Published 2020-02-25T14:02:01+09:00
JVNDB-2019-014137
Improper Access Control Vulnerability in RICOH printers
Published 2020-02-25T15:44:26+09:00
JVNDB-2019-014138
Improper Authentication Vulnerability in RICOH printers
Published 2020-02-25T15:47:18+09:00
JVNDB-2019-014437
Privilege escalation vulnerability in multiple RICOH printer drivers
Published 2020-02-25T15:29:12+09:00
JVNDB-2022-000067
Installer of Ricoh Device Software Manager may insecurely load Dynamic Link Libraries
Published 2022-08-29T15:57:15+09:00
JVNDB-2022-000089
RICOH Aficio SP 4210N vulnerable to cross-site scripting
Published 2022-11-17T11:15:29+09:00
JVNDB-2023-002111
Printer Driver Packager NX creates driver installation packages without modification detection
Published 2023-06-15T16:06:07+09:00
JVNDB-2024-000070
Out-of-bounds write vulnerability in Ricoh MFPs and printers
Published 2024-07-10T14:16:16+09:00
JVNDB-2024-000083
Firmware update for RICOH JavaTM Platform resets the TLS configuration
Published 2024-08-06T15:13:58+09:00
<N/A> : sysadm

Public sources document default credentials associated with this vendor or product. No login attempt was performed.

Source: scantide_default_credentials

Typo3 Association

Vendor:
unknown
28 campaign/advisory records
FBI / IC3 campaign / regional advisory intelligence — 20
90bad38ebb1c7aa5decba7d3
Context and Recommendations to Protect Against Malicious Activity by Iranian Cyber Group Emennet Pasargad
01e9abcc28c68df5c0b4e43e
Update on SVR Cyber Operations and Vulnerability Exploitation
043985217feed0f6c41b3a2e
Threat Actors Spoofing FIFA Websites in Advance of the 2026 World Cup
1a89e7cf2bfa6441030da3d1
Incident Response Guide: Water and Wastewater Sector
1b5d04246888741d5b11f46b
Cyber Actors Target US Election Officials with Invoice-Themed Phishing Campaign to Harvest Credentials
2d8d9bc13ebc018f2f442e1b
Top Cyber Actions for Securing Water Systems
35aef6c52a456203f20d3c21
#StopRansomware: BlackSuit (Royal) Ransomware
39d3ecb019fe628d22c38e5c
Great Odds, High Risk: The FBI Encourages U.S. Bettors to Know the Risks of Illegal Gambling — FBI An official website of the United States government. Here's how you know Official websites use .gov A .gov website belongs to an official government organization in the United States. Secure .gov websites use HTTPS A lock ( ) or https:// means you've safely connected to the .gov website. Share sensit
4780ab778103ec39f0d8c2bb
Identification and Disruption of QakBot Infrastructure
4a77421584ae224d44a86061
Iran-based Cyber Actors Enabling Ransomware Attacks on US Organizations
6739b6e1a2c41c9e2887162c
Increased Truebot Activity Infects U.S. and Canada Based Networks
6b7fcdab85dd3eee33a982e5
Hacker Com: Cyber Criminal Subset of The Community (Com) is a Rising Threat to Youth Online
7297531ea4c3021b61b8df9a
Great Odds, High Risk: The FBI Encourages U.S. Bettors to Know the Risks of Illegal Gambling
76a8ac4c31c68791b4c383d8
Defending OT Operations Against Ongoing Pro-Russia Hacktivist Activity
775da2590185c9860fe554ff
The Case for Memory Safe Roadmaps
FBI_IC3-260407.pdf
TLP:CLEAR Co-Authored by: Product ID: AA26-097A Iranian-Affiliated Cyber Actors Exploit Programmable Logic Controllers Across US Critical Infrastructure Publication: April 7, 2026 Federal Bureau of Investigation Cybersecurity and Infrastruc
FBI_IC3-260722.pdf
TLP:CLEAR Co-Authored by: Product ID: AA26-097A Iranian-Affiliated Cyber Actors Exploit Programmable Logic Controllers Across US Critical Infrastructure Publication: April 7, 2026 Last Update: July 22, 2026 Federal Bureau of Investigation D
a1ec2d34be04b293b9297f23
#StopRansomware: LockBit 3.0 Ransomware Affiliates Exploit CVE 2023-4966 Citrix Bleed Vulnerability
ae0dbc0809743eb835698806
Resources
cf6253d777ef9c82747f7cd4
Advanced Persistent Threat Actors Targeting U.S. Think Tanks
CERT-EU campaign / regional advisory intelligence — 8
03b7a54ee5ce9e82f09fe828
Cyber Security Brief 23-09 - August 2023 Monday, September 04, 2023 12:20:00 PM CEST Cyber Security Briefs are monthly executive reports that aim to present an overview of the most relevant developments in cyber security, based exclusively on open sources, with a view to inform political leadership and senior management in its constituency. Additional information on any item in this Brief can be provided upon request. Cyber Security Briefs are TLP:CLEAR.
134ff9b67400d8a3bb280abb
2022-035: Critical Remote Code Execution in Zyxel Products Tuesday, May 17, 2022 10:02:00 AM CEST In April 2022, a security researcher from Rapid7 discovered and reported a vulnerability that affects Zyxel firewall and VPN devices for business (advisory publicly released on 12th May 2022). Tracked as CVE-2022-30525 with a CVSS score of 9.8, a successful exploitation of this vulnerability allows an unauthenticated and remote attacker to achieve code execution as the "nobody" user.A public exploit
2478e8aca48921497bf1e2c7
Cyber Security Brief 23-10 - September 2023 Wednesday, October 04, 2023 10:50:00 AM CEST Cyber Security Briefs are monthly executive reports that aim to present an overview of the most relevant developments in cyber security, based exclusively on open sources, with a view to inform political leadership and senior management in its constituency. Additional information on any item in this Brief can be provided upon request. Cyber Security Briefs are TLP:CLEAR.
8372f131e98bed82bc2db0e8
Cyber Brief 25-05 - April 2025 Friday, May 02, 2025 05:00:00 PM CEST Cyber Briefs are monthly executive reports that aim to present an overview of the most relevant developments in cyber security, based exclusively on open sources, with a view to inform political leadership and senior management in its constituency. Additional information on any item in this Brief can be provided upon request. Cyber Briefs are TLP:CLEAR.
863a0d28df38c4f7b62953c7
Cyber Brief - August 2022 Monday, October 03, 2022 10:10:00 PM CEST Cyber Briefs are monthly executive reports that aim to present an overview of the most relevant developments in cyber security, based exclusively on open sources, with a view to inform political leadership and senior management in its constituency. Additional information on any item in this Brief can be provided upon request. Cyber Briefs are TLP:WHITE.
8b81a463e5fe32eccbc5ed71
2017-021: KRACK - Key Reinstallation Attacks: Breaking WPA2 Tuesday, October 17, 2017 04:27:00 PM CEST Researchers in the KU Leuven University have discovered a serious weaknesses in WPA2, a protocol that secures all modern protected Wi-Fi networks. An attacker within the range of the Wi-Fi of the victim can exploit these weaknesses using key reinstallation attack (KRACK). Attackers can use this attack to read information that was previously assumed to be safely encrypted. The weakness was found
9c4326fccb64c36af04a977e
Cyber Brief 26-05 - April 2026 Monday, May 04, 2026 05:00:00 PM CEST Cyber Briefs are monthly executive reports that aim to present an overview of the most relevant developments in cyber security, based exclusively on open sources, with a view to inform political leadership and senior management in its constituency. Additional information on any item in this Brief can be provided upon request. Cyber Briefs are TLP:CLEAR.
a616fef455d4f90fbdff47fb
Cyber Threat Intelligence Framework Wednesday, April 08, 2026 06:00:00 PM CEST Cyber Threat Intelligence Framework
admin : [blank]

Public sources document default credentials associated with this vendor or product. No login attempt was performed.

Source: scantide_default_credentials

SafeNet Sentinel EMS (mssql)

Vendor:
unknown
14 campaign/advisory records
FBI / IC3 campaign / regional advisory intelligence — 3
d739e7f21758c959e3826e34
Mitigating Log4Shell and Other Log4j-Related Vulnerabilities
FBI_IC3-260818.pdf
TLP:CLEAR Co-Authored by: Product ID: AA25-071A #StopRansomware: Medusa Ransomware Publication: March 12, 2025 Last Updated: August 18, 2026 Cybersecurity and Infrastructure Security Agency Federal Bureau of Investigation Department of Heal
380aa4f55bbd4e9e43edecb9
Russian Foreign Intelligence Service (SVR) Exploiting JetBrains TeamCity CVE Globally
CERT-EU campaign / regional advisory intelligence — 11
cd78ff783f36db815eeb1c8c
Cyber Brief - May 2022 Wednesday, June 01, 2022 02:08:00 PM CEST Cyber Briefs are monthly executive reports that aim to present an overview of the most relevant developments in cyber security, based exclusively on open sources, with a view to inform political leadership and senior management in its constituency. Additional information on any item in this Brief can be provided upon request. Cyber Briefs are TLP:WHITE.
2478e8aca48921497bf1e2c7
Cyber Security Brief 23-10 - September 2023 Wednesday, October 04, 2023 10:50:00 AM CEST Cyber Security Briefs are monthly executive reports that aim to present an overview of the most relevant developments in cyber security, based exclusively on open sources, with a view to inform political leadership and senior management in its constituency. Additional information on any item in this Brief can be provided upon request. Cyber Security Briefs are TLP:CLEAR.
5ae0dac2996931f7562a35de
Cyber Security Brief 24-03 - February 2024 Friday, March 01, 2024 04:00:00 PM CET Cyber Security Briefs are monthly executive reports that aim to present an overview of the most relevant developments in cyber security, based exclusively on open sources, with a view to inform political leadership and senior management in its constituency. Additional information on any item in this Brief can be provided upon request. Cyber Security Briefs are TLP:WHITE.
61581693f5f95b70dbfd5d0e
2025-027: Critical Vulnerabilities in Microsoft SharePoint Thursday, July 24, 2025 11:03:42 AM CEST On July 19, 2025, Microsoft released an out-of-bound advisory addressing two vulnerabilities on Microsoft SharePoint, one of which being rated as critical and allowing unauthenticated remote attacker to execute arbitrary code on vulnerable systems. These vulnerabilities apply to on-premises SharePoint Servers only. SharePoint Online in Microsoft 365 is not impacted. These critical flaws are active
81584383d86765a515d350e9
Cyber Security Brief 23-06 - May 2023 Thursday, June 01, 2023 04:20:00 PM CEST Cyber Security Briefs are monthly executive reports that aim to present an overview of the most relevant developments in cyber security, based exclusively on open sources, with a view to inform political leadership and senior management in its constituency. Additional information on any item in this Brief can be provided upon request. Cyber Security Briefs are TLP:CLEAR.
e174a70be7fbff2ccdbe4f99
Cyber Security Brief 23-07 - June 2023 Monday, July 03, 2023 11:55:00 AM CEST Cyber Security Briefs are monthly executive reports that aim to present an overview of the most relevant developments in cyber security, based exclusively on open sources, with a view to inform political leadership and senior management in its constituency. Additional information on any item in this Brief can be provided upon request. Cyber Security Briefs are TLP:CLEAR.
e91000cefe6040915dcab0ca
2022-039: UPDATE: Follina Vulnerability in Microsoft Office Products Monday, May 30, 2022 12:59:00 PM CEST On the 29th of May 2022, the Nao_Sec team, an independent Cyber Security Research Team, discovered a malicious Office document shared on Virustotal. This document is using an unusual, but known scheme to infect its victims. The scheme was not detected as malicious by some EDR, like Microsoft Defender for Endpoint. This vulnerability could lead to code execution without the need of user inte
0a60241a2ab097d6dfe3907e
2024-028: Vulnerabilities in Fortinet Products Thursday, March 14, 2024 05:49:32 PM CET On March 12, 2024, Fortinet released fixes for three vulnerabilities affecting some of their products. The vulnerabilities could allow an unauthenticated attacker to execute unauthorised code or commands via specifically crafted requests. It is recommended upgrading affected software as soon as possible.
9c4326fccb64c36af04a977e
Cyber Brief 26-05 - April 2026 Monday, May 04, 2026 05:00:00 PM CEST Cyber Briefs are monthly executive reports that aim to present an overview of the most relevant developments in cyber security, based exclusively on open sources, with a view to inform political leadership and senior management in its constituency. Additional information on any item in this Brief can be provided upon request. Cyber Briefs are TLP:CLEAR.
ea61f1a5c038c8c69b6b9bd6
Cyber Brief 26-06 - May 2026 Tuesday, June 02, 2026 06:00:00 PM CEST Cyber Briefs are monthly executive reports that aim to present an overview of the most relevant developments in cyber security, based exclusively on open sources, with a view to inform political leadership and senior management in its constituency. Additional information on any item in this Brief can be provided upon request. Cyber Briefs are TLP:CLEAR.
fcc319d3b8b201394c9cc49c
Cyber Brief 26-07 - June 2026 Wednesday, July 01, 2026 04:00:00 PM CEST Cyber Briefs are monthly executive reports that aim to present an overview of the most relevant developments in cyber security, based exclusively on open sources, with a view to inform political leadership and senior management in its constituency. Additional information on any item in this Brief can be provided upon request. Cyber Briefs are TLP:CLEAR.
sa : [blank]

Public sources document default credentials associated with this vendor or product. No login attempt was performed.

Source: scantide_default_credentials

WebLogic Process Integrator

Vendor:
· Model: WebLogic Process Integrator
unknown
18 upcoming vendor advisories 55 campaign/advisory records
FBI / IC3 campaign / regional advisory intelligence — 20
c1e6dfe7f5ede874b7f6049b
2022 Top Routinely Exploited Vulnerabilities
25091f9b0f59b31c2bd98141
Iranian State Actors Conduct Cyber Operations Against the Government of Albania
fa89754768997e9e243a4438
North Korea Cyber Group Conducts Global Espionage Campaign to Advance Regime's Military and Nuclear Programs
32fea06933ed880e2baf94a5
Cyber Criminals Increasingly Exploit Vulnerabilities in Decentralized Finance Platforms to Obtain Cryptocurrency, Causing Investors to Lose Money
02c564e5d11e235eccef00f3
New Sandworm malware Cyclops Blink replaces VPNFilter
034b6dd4edcdf314784d621e
Unpatched and Outdated Medical Devices Provide Cyber Attack Opportunities
0656fd99c93dfd5a6bca805c
Just So You Know: Ransomware Disruptions during Voting Periods Will Not Impact the Security and Resiliency of Vote Casting or Counting
0698638c72fa1363ede20ec4
2021 Trends Show Increased Globalized Threat of Ransomware
0a2ed3f904e1b539478b556c
APT40 Advisory: PRC MSS tradecraft in action
0dc584846605837f1c8a21d5
Just So You Know: False Claims of Hacked Voter Information Likely Intended to Sow Distrust of U.S. Elections — FBI An official website of the United States government. Here's how you know Official websites use .gov A .gov website belongs to an official government organization in the United States. Secure .gov websites use HTTPS A lock ( ) or https:// means you've safely connected to the .gov websi
11c95addfb97b7069dc5873a
Compromise of Microsoft Exchange Server
11f725160c85af3ba01849cc
People's Republic of China State-Sponsored Cyber Actor Living off the Land to Evade Detection
1293a5f384189b121e72eaea
Suspected PRC Cyber Actors Continue to Globally Exploit Barracuda ESG Zero-Day Vulnerability
1425b84a538a19f525596083
Tech Support Scam
1499297aad75b4e344422d39
#StopRansomware: Royal Ransomware
18b1a5dc6a6d45c83187f7ca
Tactics, Techniques, and Procedures of Indicted State-Sponsored Russian Cyber Actors Targeting the Energy Sector
18e9b4a33f64684443f98e6c
Malicious Actors Exploit CVE-2023-27350 in PaperCut MF and NG
1a89e7cf2bfa6441030da3d1
Incident Response Guide: Water and Wastewater Sector
1cabacddc320508fb266e21c
Cyber Actors Target K-12 Distance Learning Education to Cause Disruptions and Steal Data
1efa1000eaeeb618a2350cd3
Threats Associated with the Israel-HAMAS Conflict
CERT-EU campaign / regional advisory intelligence — 20
aa9b2491c54a8ce983f371e9
2021-002: Critical Vulnerabilities in Multiple Oracle Products Wednesday, January 20, 2021 03:04:00 PM CET Oracle has published an advisory about hundreds of critical vulnerabilities are affecting several of its products. Many of the vulnerabilities can be remotely exploited without authentication and without user interaction. Expedient patching of the affected products is highly recommended.
101e1f0f11d0be1353a3e8f6
Cyber Brief 25-12 - November 2025 Tuesday, December 02, 2025 04:00:00 PM CET Cyber Briefs are monthly executive reports that aim to present an overview of the most relevant developments in cyber security, based exclusively on open sources, with a view to inform political leadership and senior management in its constituency. Additional information on any item in this Brief can be provided upon request. Cyber Briefs are TLP:CLEAR.
1b0e1f9069dff7138fba17b4
2020-054: Critical Vulnerability in Oracle WebLogic Server Tuesday, November 03, 2020 04:13:00 PM CET On the 1st of November 2020, Oracle released an out-of-band patch to address a critical vulnerability (CVSS score 9.8) that has been assigned CVE-2020-14750. According to Oracle, this bug is linked to the vulnerability CVE-2020-14882. However, Oracle did not provide any information about the relation between both of the security flaws. The CVE-2020-14750 vulnerability could allow a non-authentic
2d9da3e5556cc55032f0b42f
2021-037: Critical Vulnerabilities in Oracle WebLogic Server Thursday, July 22, 2021 04:24:00 PM CEST Within the Critical Patch Update for July 2021 addressing hundreds of vulnerabilities across multiple products, Oracle released information about critical vulnerabilities affecting WebLogic Server.
3d5dadd623e642eb42c811ef
2019-010: UPDATE: Oracle WebLogic 0-day Vulnerability Friday, April 26, 2019 05:00:00 PM CEST A highly critical, zero-day vulnerability in Oracle WebLogic server was disclosed. Some attackers might have already started exploiting it in the wild. The vulnerability potentially allows attackers to remotely execute arbitrary commands. Oracle has issued an out-of-band security update to address this vulnerability.
427c825a3f797f5dd34544e0
2020-053: Critical Vulnerability in Oracle WebLogic Server Friday, October 30, 2020 05:38:00 PM CET In October, within the monthly Critical Patch Update Advisory addressing hundreds of vulnerabilities, Oracle released an update about a critical vulnerability affecting WebLogic Server. This vulnerability may allow unauthenticated attackers with network access via HTTP to achieve total compromise and takeover of vulnerable Oracle WebLogic Servers. This bug has been assigned CVE-2020-14882 and has
65091666d8e6bfcaa5d1f9af
2019
65c0f9d2753fd4f42c81979a
2022
a0018c749f30221cebfa3a3c
2020
b26f28de9b641cad7d4df2cb
2020-004: Critical Vulnerabilities in Multiple Oracle Products Wednesday, January 15, 2020 12:57:00 PM CET Oracle has published an advisory about hundreds of critical vulnerabilities that are affecting several of its products. Many of the vulnerabilities can be remotely exploited without authentication and without user interaction. Expedient patching of the affected products is highly recommended.
d379c4be4846d1ec6b3611c5
2012-0013: Denial of Service Vulnerability in Oracle WebLogic Server, Application Server (OC4J) and iPlanet Web Server Thursday, February 02, 2012 03:15:00 PM CET Oracle has released a security advisory about a denial of service vulnerability in Oracle WebLogic Server, Oracle Application Server (OC4J) and Oracle iPlanet Web Server due to hashing collisions. No authentication is required to exploit this vulnerability, so it may be exploited over a network without the need for a username and passw
d3eb32fb0c1ced517261461f
2018
d5e743aa7be8c37f1b674811
2018-018: WebLogic Vulnerability Exploited In The Wild Thursday, July 26, 2018 05:00:00 PM CEST Recently Oracle released patches for vulnerability CVE-2018-2893. This vulnerability allows an unauthenticated attacker to compromise Oracle WebLogic Server. Exploits were published on GitHub and on other websites after the announcement of the security updates. There were reported attacks against vulnerable instances.
f1ddec25aa9b68ee9d88620f
2020-026: Critical Oracle WebLogic Server Vulnerability Exploited Tuesday, May 12, 2020 06:08:00 PM CEST In April, within the monthly Critical Patch Update Advisory addressing hundreds of vulnerabilities, Oracle released an update about a critical vulnerability affecting WebLogic Server. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Oracle WebLogic. Authentication is not required to exploit this vulnerability. This bug, assigned with CVE-2020-2
05bd242fd3f8859308bab2f8
2013-053: Oracle Java SE Critical Patch Update - June 2013 Friday, June 21, 2013 02:59:00 PM CEST The Oracle Java SE Critical Patch Update [1] for June 2013 were released on.
0b03f2f7f8921c77fce46a8f
2014-169: NEW SSLv3 Padding Oracle On Downgraded Legacy Encryption attack Thursday, November 20, 2014 10:09:00 AM CET The SSL protocol 3.0, as used in OpenSSL and other products, uses non-deterministic CBC padding, which makes it easier for man-in-the-middle attackers to obtain clear text data via a padding-oracle attack, aka the "POODLE" issue.
1424ba9a397110ec1688ac22
2012-0073: Oracle Java SE Critical Patch Update Advisory - June 2012 Wednesday, June 13, 2012 04:52:00 PM CEST A Critical Patch Update is a collection of patches for multiple security vulnerabilities. The Critical Patch Update for Java SE also includes non-security fixes.
164e9b5c225d1223c305e30c
Cyber Brief 25-11 - October 2025 Saturday, November 01, 2025 04:00:00 PM CET Cyber Briefs are monthly executive reports that aim to present an overview of the most relevant developments in cyber security, based exclusively on open sources, with a view to inform political leadership and senior management in its constituency. Additional information on any item in this Brief can be provided upon request. Cyber Briefs are TLP:CLEAR.
1b73dcbba2ab33095336de4b
2022-006: Critical Vulnerabilities in Multiple Oracle Products Thursday, January 20, 2022 06:24:00 PM CET On January 18th, Oracle released their quarterly Critical Patch Update advisory, a collection of patches that addresses hundreds of critical security flaws, affecting several of their products. Many of these vulnerabilities may be remotely exploited without the need for user credentials. It is therefore highly recommended to apply the security patches without delay.
1fcf21fda66910438380068c
2013
JVN / Japan campaign / regional advisory intelligence — 15
JVNDB-2005-000727
mod_imap cross-site scripting vulnerability
Published 2008-05-21T00:00:00+09:00
JVNDB-2007-000819
Cross-site scripting vulnerability in Apache HTTP Server "mod_imap" and "mod_imagemap"
Published 2008-05-21T00:00:00+09:00
JVNDB-2008-000040
Directory traversal vulnerability in WebLogic Server and WebLogic Express plug-ins
Published 2008-07-24T14:22:29+09:00
JVNDB-2009-000007
Oracle WebLogic Server vulnerable to cross-site scripting
Published 2009-01-20T16:45:07+09:00
JVNDB-2009-002069
Oracle iPlanet Web Server information disclosure vulnerability
Published 2011-07-25T18:06:11+09:00
JVNDB-2010-000004
Oracle Application Server vulnerable to cross-site scripting
Published 2010-01-14T21:24:17+09:00
JVNDB-2010-000042
Cross-site Request Forgery Vulnerability in Oracle iPlanet Web Server
Published 2010-10-18T19:37:08+09:00
JVNDB-2010-000054
Flash Player access restriction bypass vulnerability
Published 2010-11-09T19:59:22+09:00
JVNDB-2012-000007
Oracle WebLogic Server vulnerable to cross-site scripting
Published 2012-01-20T15:37:30+09:00
JVNDB-2013-000070
Oracle Outside In vulnerable to buffer overflow
Published 2013-07-17T13:45:49+09:00
JVNDB-2013-000071
Oracle Outside In vulnerable to denial-of-service (DoS)
Published 2013-07-17T13:56:43+09:00
JVNDB-2013-003391
Oracle Enterprise Manager vulnerable to cross-site scripting
Published 2013-07-22T15:00:03+09:00
JVNDB-2013-003469
Apache Struts vulnerable to remote command execution
Published 2013-09-06T14:12:18+09:00
JVNDB-2024-000014
Oracle WebLogic Server vulnerable to HTTP header injection
Published 2024-01-24T13:53:09+09:00
JVNDB-2020-000047
JavaFX WebEngine does not properly restrict Java method execution
Published 2020-07-28T15:47:48+09:00
Upcoming ZDI vendor advisories — 18

Vendor-level advance notice: ZDI has not yet disclosed which product is affected. These entries are shown because this credential record matches the vendor; they are not findings against this product or model.

ZDI-CAN-29370 CVSS 7.8
Vendor contacted: 2026-03-31 Planned disclosure: 2026-07-29 Researcher: Dvir Gozlan
Affected product: Not yet disclosed · Open ZDI Upcoming
ZDI-CAN-29543 CVSS 7.8
Vendor contacted: 2026-04-08 Planned disclosure: 2026-08-06 Researcher: Mat Powell of TrendAI Zero Day Initiative
Affected product: Not yet disclosed · Open ZDI Upcoming
ZDI-CAN-29542 CVSS 7.8
Vendor contacted: 2026-04-08 Planned disclosure: 2026-08-06 Researcher: Mat Powell of TrendAI Zero Day Initiative
Affected product: Not yet disclosed · Open ZDI Upcoming
ZDI-CAN-29541 CVSS 7.8
Vendor contacted: 2026-04-08 Planned disclosure: 2026-08-06 Researcher: Mat Powell of TrendAI Zero Day Initiative
Affected product: Not yet disclosed · Open ZDI Upcoming
ZDI-CAN-31766 CVSS 7.8
Vendor contacted: 2026-06-10 Planned disclosure: 2026-10-08 Researcher: Mat Powell of TrendAI Zero Day Initiative
Affected product: Not yet disclosed · Open ZDI Upcoming
ZDI-CAN-31765 CVSS 7.8
Vendor contacted: 2026-06-10 Planned disclosure: 2026-10-08 Researcher: Mat Powell of TrendAI Zero Day Initiative
Affected product: Not yet disclosed · Open ZDI Upcoming
ZDI-CAN-31767 CVSS 7.8
Vendor contacted: 2026-06-10 Planned disclosure: 2026-10-08 Researcher: Mat Powell of TrendAI Zero Day Initiative
Affected product: Not yet disclosed · Open ZDI Upcoming
ZDI-CAN-31777 CVSS 7.8
Vendor contacted: 2026-06-10 Planned disclosure: 2026-10-08 Researcher: Mat Powell of TrendAI Zero Day Initiative
Affected product: Not yet disclosed · Open ZDI Upcoming
ZDI-CAN-31842 CVSS 9.3
Vendor contacted: 2026-06-16 Planned disclosure: 2026-10-14 Researcher: Lucas Miller of TrendAI Research
Affected product: Not yet disclosed · Open ZDI Upcoming
ZDI-CAN-32013 CVSS 9.9
Vendor contacted: 2026-06-23 Planned disclosure: 2026-10-21 Researcher: Bobby Gould (@bobbygould5) of TrendAI Zero Day Initiative
Affected product: Not yet disclosed · Open ZDI Upcoming
ZDI-CAN-29751 CVSS 7.5
Vendor contacted: 2026-06-25 Planned disclosure: 2026-10-23 Researcher: Team Amazone@229
Affected product: Not yet disclosed · Open ZDI Upcoming
ZDI-CAN-30083 CVSS 7.5
Vendor contacted: 2026-06-25 Planned disclosure: 2026-10-23 Researcher: crixer(@pwning_me)
Affected product: Not yet disclosed · Open ZDI Upcoming
ZDI-CAN-32169 CVSS 7.8
Vendor contacted: 2026-06-30 Planned disclosure: 2026-10-28 Researcher: Mat Powell of TrendAI Zero Day Initiative
Affected product: Not yet disclosed · Open ZDI Upcoming
ZDI-CAN-31121 CVSS 7.5
Vendor contacted: 2026-07-07 Planned disclosure: 2026-11-04 Researcher: Xiaobye(@xiaobye_tw) of DEVCORE Research Team
Affected product: Not yet disclosed · Open ZDI Upcoming
ZDI-CAN-30184 CVSS 7.5
Vendor contacted: 2026-07-10 Planned disclosure: 2026-11-07 Researcher: Phan Vinh Khang of Viettel Cyber Security
Affected product: Not yet disclosed · Open ZDI Upcoming
ZDI-CAN-29835 CVSS 6.1
Vendor contacted: 2026-07-10 Planned disclosure: 2026-11-07 Researcher: Xiaobye(@xiaobye_tw) of DEVCORE Research Team
Affected product: Not yet disclosed · Open ZDI Upcoming
ZDI-CAN-31532 CVSS 6.1
Vendor contacted: 2026-07-24 Planned disclosure: 2026-11-21 Researcher: vmpr0be
Affected product: Not yet disclosed · Open ZDI Upcoming
ZDI-CAN-31625 CVSS 5.3
Vendor contacted: 2026-07-24 Planned disclosure: 2026-11-21 Researcher: vmpr0be
Affected product: Not yet disclosed · Open ZDI Upcoming
system : security

Public sources document default credentials associated with this vendor or product. No login attempt was performed.

Source: scantide_default_credentials

INFOPRINT 6700 Rev. HTTP://WWW.PHENOELIT.DE/DPL/DPL.HTML

Vendor:
· Model: INFOPRINT 6700 Rev. HTTP://WWW.PHENOELIT.DE/DPL/DPL.HTML
multi
59 campaign/advisory records
FBI / IC3 campaign / regional advisory intelligence — 20
1a89e7cf2bfa6441030da3d1
Incident Response Guide: Water and Wastewater Sector
d925353134f317a5506aa90c
Ongoing Cyber Threats to U.S. Water and Wastewater Systems
36b4ec7d77002ad7f7aa6d7e
Guidelines for secure AI system development
00909f285745b657db9d9fe7
Multinational Non-Governmental Organizations Potentially Exploited in Aftermath of Earthquakes Affecting Turkey and Syria
01e9abcc28c68df5c0b4e43e
Update on SVR Cyber Operations and Vulnerability Exploitation
02c564e5d11e235eccef00f3
New Sandworm malware Cyclops Blink replaces VPNFilter
07e8dad684aa5ddf5f71550d
Motor Vehicles Increasingly Vulnerable to Remote Exploits
11c95addfb97b7069dc5873a
Compromise of Microsoft Exchange Server
1499297aad75b4e344422d39
#StopRansomware: Royal Ransomware
18e9b4a33f64684443f98e6c
Malicious Actors Exploit CVE-2023-27350 in PaperCut MF and NG
1cabacddc320508fb266e21c
Cyber Actors Target K-12 Distance Learning Education to Cause Disruptions and Steal Data
1e1e19419dbe954c101e3fe4
Conti Ransomware Attacks Impact Healthcare and First Responder Networks
20fccf4dc914e7de91594312
Karakurt Data Extortion Group
25091f9b0f59b31c2bd98141
Iranian State Actors Conduct Cyber Operations Against the Government of Albania
2bef98c7bdd63544bc69dc54
Indicators of Compromise Associated with LockBit 2.0 Ransomware
35aef6c52a456203f20d3c21
#StopRansomware: BlackSuit (Royal) Ransomware
3a1646c7b2f5c6b4bfcd91be
Russian Military Cyber Actors Target U.S. and Global Critical Infrastructure
3c8fc2080b77827513541387
#StopRansomware: BianLian Data Extortion Group
40843a59c9247b8a0196d552
Cyber Criminals Use Fake Job Listings To Target Applicants' Personally Identifiable Information
427b50ed882d3c9a0378d316
2023 Top Routinely Exploited Vulnerabilities
CERT-EU campaign / regional advisory intelligence — 20
5cc2ed95629003380b8e47d0
2011
9c97832c4deff24c44466de4
Cyber Security Brief 23-08 - July 2023 Tuesday, August 01, 2023 08:30:00 PM CEST Cyber Security Briefs are monthly executive reports that aim to present an overview of the most relevant developments in cyber security, based exclusively on open sources, with a view to inform political leadership and senior management in its constituency. Additional information on any item in this Brief can be provided upon request. Cyber Security Briefs are TLP:CLEAR.
a07ff9c64a8eaaac05972609
2012-0102: IBM WebSphere MQ File Transfer Edition Web Gateway insufficient access control Friday, August 17, 2012 03:34:00 PM CEST When using the web gateway, an authenticated user is able to access other users' files without further access control if the URL of the file is known. The URL for a file contains non guessable elements.
decebe71a58113ba6e5f1c3b
2012
e4d65c698fc358af977b08bd
Cyber Security Brief 24-04 - March 2024 Wednesday, April 03, 2024 12:30:00 PM CEST Cyber Security Briefs are monthly executive reports that aim to present an overview of the most relevant developments in cyber security, based exclusively on open sources, with a view to inform political leadership and senior management in its constituency. Additional information on any item in this Brief can be provided upon request. Cyber Security Briefs are TLP:CLEAR.
ea61f1a5c038c8c69b6b9bd6
Cyber Brief 26-06 - May 2026 Tuesday, June 02, 2026 06:00:00 PM CEST Cyber Briefs are monthly executive reports that aim to present an overview of the most relevant developments in cyber security, based exclusively on open sources, with a view to inform political leadership and senior management in its constituency. Additional information on any item in this Brief can be provided upon request. Cyber Briefs are TLP:CLEAR.
00fcbc2726cc1783631565f5
2021-034: Vulnerabilities in Cisco Products Friday, July 09, 2021 07:29:00 AM CEST On July 7, Cisco released security updates to address several security vulnerabilities. This list includes vulnerabilities rated High affecting Cisco Business Process Automation (BPA) with a CVSS score of 8.8 out of 10 and a vulnerability rated Medium affecting Cisco Adaptive Security Device Manager (ASDM) with a CVSS score of 7.5 out of 10.Vulnerabilities in Cisco Business Process Automation (BPA) could allow an
021dad8bb0c4c9076a95ac7d
2017-012: UPDATE! WannaCry Ransomware Campaign Exploiting SMB Vulnerability Monday, May 22, 2017 03:46:00 PM CEST A large ransomware campaign has been observed since Friday, May 12th, 2017. The payload delivered is a variant of ransomware malware called WannaCry. It appears to infect computers through a recent SMB vulnerability in Microsoft Windows operating system (CVE-2017-0145).
028690869a5d7895c1925e08
2021-065: Vulnerabilities in VMware Products Thursday, November 25, 2021 09:55:00 AM CET On November 23, VMWare has released the VMSA-2021-0027 advisory that addresses two vulnerabilities in vCenter Server and Cloud Foundation. An attacker could exploit these vulnerabilities to read sensitive files ("CVE-2021-21980" - unauthorised arbitrary file read vulnerability) or to induce the server to make connections to arbitrary destinations ("CVE-2021-22049" - SSRF vulnerability).
03ba6a9a29ff7ce507a7b36d
2025-033: Critical Vulnerabilities in Citrix NetScaler Products Tuesday, August 26, 2025 05:40:17 PM CEST On 26 August 2025, Citrix released a security advisory addressing one critical and two high severity vulnerabilities in NetScaler ADC and NetScaler Gateway. Citrix warns that exploits of the critical vulnerability, CVE-2025-7775, have been observed on unmitigated appliances. It is recommended to update affected assets as soon as possible.
03f275e81a7d188dbbd18cbc
2018-011: Cisco Products Multiple Vulnerabilities Thursday, April 19, 2018 04:36:00 PM CEST On the 17th and 18th of April 2018, Cisco has released several updates to address vulnerabilities affecting multiple products in which a remote attacker can exploit these vulnerabilities to trigger cross site scripting, denial of service, remote code execution, security restriction bypass and sensitive information disclosure on the targeted system.
0463bc1aca415ae34bacd02a
2021-009: Critical Vulnerabilities in Cisco Products Thursday, February 04, 2021 09:35:00 PM CET Cisco has published an advisory about several vulnerabilities affecting various Cisco Products. These vulnerabilities could lead to remote code execution, privilege escalation, directory traversal, file overwrite or denial of service. While Cisco is not aware of any malicious exploit in the wild, it is highly recommended to patch the affected products.
04fc97c8f2852a360cdf4afc
2023
07b4aa1a9c0a06866509a925
2024-018: Critical Vulnerabilities in FortiOS Friday, February 09, 2024 09:56:16 AM CET On February 9, 2024, Fortinet released an advisory regarding critical vulnerabilities affecting FortiOS that, if exploited, would allow a remote and unauthenticated to execute code on the affected device. One of the critical vulnerabilities is potentially being exploited in the wild. It is recommended updating as soon as possible.
07f93ac177a174d99635789b
2020-036: Critical Cisco Vulnerabilities Thursday, July 16, 2020 12:06:00 PM CEST Cisco released 31 Security Advisories for vulnerabilities affecting its products. Five of them are rated critical with CVSS Score 9.8. In particular, critical vulnerabilities affect: telnet service of firewall routers (CVE-2020-3330), web-based management interface of routers (CVE-2020-3323, CVE-2020-3144, and CVE-2020-3331), and web management interface of Cisco Prime License Manager (PLM) software (CVE-2020-3140)
08c9ebf0229710879177a16f
2025-041: Critical Security Vulnerability in React Server Components Thursday, December 04, 2025 02:50:51 PM CET On December 3, 2025, the React Team publicly disclosed a critical security vulnerability affecting React Server Components (RSC) and related packages. The vulnerability allows for unauthenticated remote code execution (RCE) via maliciously crafted HTTP requests. It is recommended to update all affected component packages and any frameworks that integrate them.
0a60241a2ab097d6dfe3907e
2024-028: Vulnerabilities in Fortinet Products Thursday, March 14, 2024 05:49:32 PM CET On March 12, 2024, Fortinet released fixes for three vulnerabilities affecting some of their products. The vulnerabilities could allow an unauthenticated attacker to execute unauthorised code or commands via specifically crafted requests. It is recommended upgrading affected software as soon as possible.
100bdd71ea7bd8e5ed96180d
2021-015: UPDATE: Critical Vulnerabilities Affecting F5 Devices Thursday, March 11, 2021 09:30:00 AM CET On the 10th or March 2021, F5 released several security advisories, including four identified as critical.One of the vulnerabilities allows an unauthenticated attacker with network access to the iControl REST interface, through the BIG-IP management interface and self IP addresses, to execute arbitrary system commands, create or delete files, and disable services.Another of the vulnerabilitie
10f3205f97e0128801acb4b1
2013-0100: Cisco ASA Denial of service Wednesday, December 11, 2013 04:22:00 PM CET A vulnerability in the Cisco Adaptive Security Appliance (ASA) Software could allow an unauthenticated, remote attacker to cause an affected system to become unresponsive to management session requests via SSH, Telnet, HTTP, and HTTPS.
115ad5450cb1542683025ddb
2023-077: Microsoft October 2023 Patch Tuesday Wednesday, October 11, 2023 05:55:56 PM CEST Microsoft has released its October 2023 Patch Tuesday Security Updates, addressing a total of 103 CVEs among which 12 are rated as critical, and 91 are rated as important. Microsoft also reported that two vulnerabilities are actively exploited.
JVN / Japan campaign / regional advisory intelligence — 19
JVNDB-2005-000705
Fujitsu Java Runtime Environment reflection API vulnerability
Published 2008-05-21T00:00:00+09:00
JVNDB-2005-000706
Fujitsu Java Runtime Environment reflection API vulnerability
Published 2008-05-21T00:00:00+09:00
JVNDB-2005-000707
Fujitsu Java Runtime Environment reflection API vulnerability
Published 2008-05-21T00:00:00+09:00
JVNDB-2005-000727
mod_imap cross-site scripting vulnerability
Published 2008-05-21T00:00:00+09:00
JVNDB-2005-000776
Java Cryptography Extension 1.2.1 (JCE 1.2.1) will no longer function properly after July 28, 2005 due to the expiration of its digital certificate
Published 2008-05-21T00:00:00+09:00
JVNDB-2007-000802
Lotus Domino cross-site scripting vulnerability
Published 2008-05-21T00:00:00+09:00
JVNDB-2007-000819
Cross-site scripting vulnerability in Apache HTTP Server "mod_imap" and "mod_imagemap"
Published 2008-05-21T00:00:00+09:00
JVNDB-2008-001043
X.Org Foundation X server buffer overflow vulnerability
Published 2008-06-13T17:11:26+09:00
JVNDB-2011-000016
IBM DB2 vulnerable to denial-of-service (DoS)
Published 2011-03-04T19:29:37+09:00
JVNDB-2011-000017
IBM WebSphere Application Server vulnerable to denial-of-service (DoS)
Published 2011-03-04T19:29:20+09:00
JVNDB-2011-000018
IBM Lotus vulnerable to denial-of-service (DoS)
Published 2011-03-04T19:28:42+09:00
JVNDB-2013-000004
WebSphere Application Server (WAS) vulnerable to cross-site scripting
Published 2013-01-25T12:32:36+09:00
JVNDB-2013-000030
Lotus Domino vulnerable to denial-of-service (DoS)
Published 2013-03-28T12:32:39+09:00
JVNDB-2013-000070
Oracle Outside In vulnerable to buffer overflow
Published 2013-07-17T13:45:49+09:00
JVNDB-2013-000071
Oracle Outside In vulnerable to denial-of-service (DoS)
Published 2013-07-17T13:56:43+09:00
JVNDB-2026-000038
Installer for IBM Trusteer Rapport may insecurely load Dynamic Link Libraries
Published 2026-03-17T14:57:53+09:00
JVNDB-2007-000395
Homepage Builder sample CGI programs vulnerable to OS command injection
Published 2008-05-21T00:00:00+09:00
JVNDB-2008-000011
Internet Scanner reporting engine vulnerable to cross-site scripting
Published 2008-05-21T00:00:00+09:00
JVNDB-2025-000104
Multiple vulnerabilities in GNU Libmicrohttpd
Published 2025-11-10T15:07:35+09:00
root : [blank]

Public sources document default credentials associated with this vendor or product. No login attempt was performed.

Source: scantide_default_credentials

ericsson acc

Vendor:
· Model: ericsson acc
multi
1 campaign/advisory record
FBI / IC3 campaign / regional advisory intelligence — 1
4ff1df702fc29c42057d8f6b
Top Routinely Exploited Vulnerabilities
[no username] : [blank]

Public sources document default credentials associated with this vendor or product. No login attempt was performed.

Source: scantide_default_credentials
References

Network cameras

Vendor:
· Model: Network cameras
unknown
1 upcoming vendor advisory 46 campaign/advisory records
FBI / IC3 campaign / regional advisory intelligence — 20
22d54aba1c3e6e05a9d1d8d1
Common Internet of Things Devices May Expose Consumers to Cyber Exploitation
24eae392c7e3a25cf0cb8d60
Ransomware Attacks Straining Local US Governments and Public Services
3a1646c7b2f5c6b4bfcd91be
Russian Military Cyber Actors Target U.S. and Global Critical Infrastructure
3ea3cb07dd4c7f0f2db3478c
2024
3ef0e143169ef8b9b75a55ea
2024 U.S. Federal Elections: The Insider Threat
57ff43de10c50b891ba950cf
Top CVEs Actively Exploited By People's Republic of China State-Sponsored Cyber Actors
7258bcf352fa4c07d85afa23
Cyber Actors Use Internet of Things Devices as Proxies for Anonymity and Pursuit of Malicious Cyber Activities
727bf4770c53f60ac4bf0c93
New Tradecraft of Iranian Cyber Group Aria Sepehr Ayandehsazan aka Emennet Pasargad
80d9ef62d337e508062cbe27
Skip to content
907c908590f218ea37bf4a97
Revised: Internet-Connected Toys Could Present Privacy and Contact Concerns for Children
9550066e70010a432e19c33e
People's Republic of China-Linked Actors Compromise Routers and IoT Devices for Botnet Operations
004e15477836566437b67760
Office of Public Affairs | Justice Department Announces Actions to Combat Two Russian State-Sponsored Cyber Criminal Hacking Groups | United States Department of Justice Skip to main content An official website of the United States government Here's how you know Here's how you know Official websites use .gov A .gov website belongs to an official government organization in the United States. Secure
01e9abcc28c68df5c0b4e43e
Update on SVR Cyber Operations and Vulnerability Exploitation
02c564e5d11e235eccef00f3
New Sandworm malware Cyclops Blink replaces VPNFilter
034b6dd4edcdf314784d621e
Unpatched and Outdated Medical Devices Provide Cyber Attack Opportunities
0395243c18e95df7d5cb774c
In Real Life (IRL) Com: Violent Subset of The Community (Com) is a Rising Threat to Youth Online — FBI An official website of the United States government. Here's how you know Official websites use .gov A .gov website belongs to an official government organization in the United States. Secure .gov websites use HTTPS A lock ( ) or https:// means you've safely connected to the .gov website. Share se
0698638c72fa1363ede20ec4
2021 Trends Show Increased Globalized Threat of Ransomware
07e7eb1322d4643ea3b7b3c7
Return to top
07e8dad684aa5ddf5f71550d
Motor Vehicles Increasingly Vulnerable to Remote Exploits
0910102e922241808c13aeb5
Alert on Cryptocurrency Money Services Businesses — FBI An official website of the United States government. Here's how you know Official websites use .gov A .gov website belongs to an official government organization in the United States. Secure .gov websites use HTTPS A lock ( ) or https:// means you've safely connected to the .gov website. Share sensitive information only on official, secure we
CERT-EU campaign / regional advisory intelligence — 20
101e1f0f11d0be1353a3e8f6
Cyber Brief 25-12 - November 2025 Tuesday, December 02, 2025 04:00:00 PM CET Cyber Briefs are monthly executive reports that aim to present an overview of the most relevant developments in cyber security, based exclusively on open sources, with a view to inform political leadership and senior management in its constituency. Additional information on any item in this Brief can be provided upon request. Cyber Briefs are TLP:CLEAR.
81584383d86765a515d350e9
Cyber Security Brief 23-06 - May 2023 Thursday, June 01, 2023 04:20:00 PM CEST Cyber Security Briefs are monthly executive reports that aim to present an overview of the most relevant developments in cyber security, based exclusively on open sources, with a view to inform political leadership and senior management in its constituency. Additional information on any item in this Brief can be provided upon request. Cyber Security Briefs are TLP:CLEAR.
8372f131e98bed82bc2db0e8
Cyber Brief 25-05 - April 2025 Friday, May 02, 2025 05:00:00 PM CEST Cyber Briefs are monthly executive reports that aim to present an overview of the most relevant developments in cyber security, based exclusively on open sources, with a view to inform political leadership and senior management in its constituency. Additional information on any item in this Brief can be provided upon request. Cyber Briefs are TLP:CLEAR.
408489f685ebe344cf418bea
Cyber Security Brief 24-02 - January 2024 Friday, February 02, 2024 12:00:00 PM CET Cyber Security Briefs are monthly executive reports that aim to present an overview of the most relevant developments in cyber security, based exclusively on open sources, with a view to inform political leadership and senior management in its constituency. Additional information on any item in this Brief can be provided upon request. Cyber Security Briefs are TLP:WHITE.
9136a85af7dac9f7b449484e
TLR 10 Years
a819b39204a06005b3b1daa9
Cyber Brief 25-07 - June 2025 Tuesday, July 01, 2025 05:00:00 PM CEST Cyber Briefs are monthly executive reports that aim to present an overview of the most relevant developments in cyber security, based exclusively on open sources, with a view to inform political leadership and senior management in its constituency. Additional information on any item in this Brief can be provided upon request. Cyber Briefs are TLP:CLEAR.
a3669f25439ea71ed1983d8c
2012-0138: Samsung and some Dell printers, Remote Disclosure of Information. Thursday, December 06, 2012 10:06:00 AM CET Samsung printers and some Dell printers manufactured for Samsung contain and snmp account that could be used to get privileged access to the devices.
c080e51ea7eda0029e795522
2017-008: Broadcom Critical Wi-Fi SoC Vulnerability in iOS and Android Friday, April 07, 2017 09:02:00 AM CEST The vulnerability resides in a widely used Wi-Fi chipset manufactured by Broadcom and used in both iOS and Android devices. An attacker within range may be able to execute arbitrary code on the Wi-Fi chip. Google Project Zero researcher Gal Beniamini, who discovered the flaw said it allowed the execution of malicious code by Wi-Fi proximity alone, requiring no user interaction [1].
decebe71a58113ba6e5f1c3b
2012
f3af06ad16c56844595e0a7d
2019-020: Simjacker Vulnerability Impacting up to 1 Billion Phone Users Friday, September 13, 2019 06:07:00 PM CEST AdaptiveMobile Security have uncovered a new and previously undetected vulnerability and associated exploits, called Simjacker. This vulnerability is currently being actively exploited. The main Simjacker attack involves an SMS containing a specific type of spyware-like code being sent to a mobile phone, which then instructs the SIM Card within the phone to "take over" the mobile p
00fcbc2726cc1783631565f5
2021-034: Vulnerabilities in Cisco Products Friday, July 09, 2021 07:29:00 AM CEST On July 7, Cisco released security updates to address several security vulnerabilities. This list includes vulnerabilities rated High affecting Cisco Business Process Automation (BPA) with a CVSS score of 8.8 out of 10 and a vulnerability rated Medium affecting Cisco Adaptive Security Device Manager (ASDM) with a CVSS score of 7.5 out of 10.Vulnerabilities in Cisco Business Process Automation (BPA) could allow an
0156a7adb3958cfad7c04e73
2021-041: Critical Vulnerability in Jira Products Friday, July 23, 2021 12:22:00 PM CEST A critical vulnerability (CVE-2020-36239) in many versions of Jira Data Center and Jira Service Management Data Center products can lead to arbitrary code execution.
021dad8bb0c4c9076a95ac7d
2017-012: UPDATE! WannaCry Ransomware Campaign Exploiting SMB Vulnerability Monday, May 22, 2017 03:46:00 PM CEST A large ransomware campaign has been observed since Friday, May 12th, 2017. The payload delivered is a variant of ransomware malware called WannaCry. It appears to infect computers through a recent SMB vulnerability in Microsoft Windows operating system (CVE-2017-0145).
028690869a5d7895c1925e08
2021-065: Vulnerabilities in VMware Products Thursday, November 25, 2021 09:55:00 AM CET On November 23, VMWare has released the VMSA-2021-0027 advisory that addresses two vulnerabilities in vCenter Server and Cloud Foundation. An attacker could exploit these vulnerabilities to read sensitive files ("CVE-2021-21980" - unauthorised arbitrary file read vulnerability) or to induce the server to make connections to arbitrary destinations ("CVE-2021-22049" - SSRF vulnerability).
03b7a54ee5ce9e82f09fe828
Cyber Security Brief 23-09 - August 2023 Monday, September 04, 2023 12:20:00 PM CEST Cyber Security Briefs are monthly executive reports that aim to present an overview of the most relevant developments in cyber security, based exclusively on open sources, with a view to inform political leadership and senior management in its constituency. Additional information on any item in this Brief can be provided upon request. Cyber Security Briefs are TLP:CLEAR.
03f275e81a7d188dbbd18cbc
2018-011: Cisco Products Multiple Vulnerabilities Thursday, April 19, 2018 04:36:00 PM CEST On the 17th and 18th of April 2018, Cisco has released several updates to address vulnerabilities affecting multiple products in which a remote attacker can exploit these vulnerabilities to trigger cross site scripting, denial of service, remote code execution, security restriction bypass and sensitive information disclosure on the targeted system.
0442e4958da9974386d3aed6
2013-0061: Authenticated Command Injection Vulnerability in Multiple Cisco Content Network and Video Delivery Products Friday, August 09, 2013 01:06:00 PM CEST Multiple Cisco content network and video delivery products contain a vulnerability when they are configured to run in central management mode.
04fc97c8f2852a360cdf4afc
2023
057fdcd62e3ec018a2633e0f
2024-072: Vulnerabilities in Ivanti EPMM Monday, July 22, 2024 10:34:56 AM CEST On July 17, 2024, Ivanti released a security advisory addressing several vulnerabilities in its EPMM solution (formerly known as MobileIron). These vulnerabilities could lead to remote code execution, authentication bypass, and sensitive information leakage. It is recommended updating as soon as possible.
060783a8f0553c4295139910
Cyber Brief 25-04 - March 2025 Wednesday, April 02, 2025 04:00:00 PM CEST Cyber Briefs are monthly executive reports that aim to present an overview of the most relevant developments in cyber security, based exclusively on open sources, with a view to inform political leadership and senior management in its constituency. Additional information on any item in this Brief can be provided upon request. Cyber Briefs are TLP:CLEAR.
Europol / EC3 campaign / regional advisory intelligence — 6
7c9f923fb2209b9afc3963b9
Police dismantle prolific ransomware cybercriminal network – The Hague, the Netherlands | Europol You need to enable JavaScript to run this app. Loading application. Please wait.
afae6f19a40f7e54a02517fa
Global operation targets NoName057(16) pro-Russian cybercrime network – The offenders targeted Ukraine and supporting countries, including many EU Member States | Europol You need to enable JavaScript to run this app. Loading application. Please wait.
c1a6dbe7dad82d4689fb14e8
Cybercrime-as-a-service takedown: 7 arrested – Operation takes down sophisticated criminal network that enabled criminals to commit serious crimes across Europe | Europol You need to enable JavaScript to run this app. Loading application. Please wait.
cc48a5b86d652879ecf009a5
Criminal phishing network resulting in over 480 000 victims worldwide busted in Spain and Latin America – First ever joint operation between Europol and the Specialised Cybercrime Centre of Ameripol | Europol You need to enable JavaScript to run this app. Loading application. Please wait.
e29d41d3cc410f6b18aa643e
GOZNYM MALWARE: CYBERCRIMINAL NETWORK DISMANTLED IN INTERNATIONAL OPERATION | Europol You need to enable JavaScript to run this app. Loading application. Please wait.
ece2d4b920b04ded952bd339
Hook, line and sinker: cybercrime network phishing bank credentials arrested in Romania – The criminal group sent phishing text messages and emails to get access to victims’ bank accounts | Europol You need to enable JavaScript to run this app. Loading application. Please wait.
Upcoming ZDI vendor advisories — 1

Vendor-level advance notice: ZDI has not yet disclosed which product is affected. These entries are shown because this credential record matches the vendor; they are not findings against this product or model.

ZDI-CAN-29432 CVSS 8.8
Vendor contacted: 2026-05-06 Planned disclosure: 2026-09-03 Researcher: Dvir Gozlan
Affected product: Not yet disclosed · Open ZDI Upcoming
root : admin

Public sources document default credentials associated with this vendor or product. No login attempt was performed.

Source: scantide_default_credentials

Mutare

Vendor:
unknown
[no username] : [blank]

Public sources document default credentials associated with this vendor or product. No login attempt was performed.

Source: scantide_default_credentials

SPEEDPORT W700

Vendor:
· Model: SPEEDPORT W700
none
4 campaign/advisory records
CERT-EU campaign / regional advisory intelligence — 4
7a8af3c6f57edf032a0f70fa
Cyber Security Brief - November 2022 Thursday, December 01, 2022 11:20:00 AM CET Cyber Security Briefs are monthly executive reports that aim to present an overview of the most relevant developments in cyber security, based exclusively on open sources, with a view to inform political leadership and senior management in its constituency. Additional information on any item in this Brief can be provided upon request. Cyber Security Briefs are TLP:WHITE.
9c97832c4deff24c44466de4
Cyber Security Brief 23-08 - July 2023 Tuesday, August 01, 2023 08:30:00 PM CEST Cyber Security Briefs are monthly executive reports that aim to present an overview of the most relevant developments in cyber security, based exclusively on open sources, with a view to inform political leadership and senior management in its constituency. Additional information on any item in this Brief can be provided upon request. Cyber Security Briefs are TLP:CLEAR.
d2a09ba23b503c7248ce411a
Cyber Security Brief 23-04 - March 2023 Monday, April 03, 2023 03:15:00 PM CEST Cyber Security Briefs are monthly executive reports that aim to present an overview of the most relevant developments in cyber security, based exclusively on open sources, with a view to inform political leadership and senior management in its constituency. Additional information on any item in this Brief can be provided upon request. Cyber Security Briefs are TLP:CLEAR.
ed09786a3d6bd296872c16a5
Cyber Brief 26-03 - February 2026 Monday, March 02, 2026 06:00:00 PM CET Cyber Briefs are monthly executive reports that aim to present an overview of the most relevant developments in cyber security, based exclusively on open sources, with a view to inform political leadership and senior management in its constituency. Additional information on any item in this Brief can be provided upon request. Cyber Briefs are TLP:CLEAR.
(none) : 0000

Public sources document default credentials associated with this vendor or product. No login attempt was performed.

Source: scantide_default_credentials

Submit a missing product

Suggestions appear in search immediately with an unreviewed community label and remain queued for moderation. Please include a public reference when possible.