Findings

Vulnerabilities

All findings with CVSS, mapped host, and Likelihood × Impact risk score.

110
Total findings
36
Critical
28
With known CVE
42
On public assets
110 of 110
Severity
Zone
Exposure
IDFindingCVEHostZoneCategoryCVSSSeverityRisk▼
V-001Apache 2.4.41 path traversalCVE-2021-41773portal-web01DMZWeb Server9.8Critical25
V-003API missing auth on /v1/students—api-gwDMZAPI/Auth9.1Critical25
V-011FortiOS SSL-VPN path traversalCVE-2018-13379vpn-gwDMZVPN9.8Critical25
V-019Apache mod_cgi RCECVE-2021-41773library-webDMZWeb Server9.8Critical25
V-020Exam portal SQLi in id param—exam-portalDMZInjection9.1Critical25
V-033PAN-OS GlobalProtect RCECVE-2024-3400firewall-perimeterDMZFirewall10Critical25
V-037S3 bucket public write access—s3-bucket-backupsCLOUDCloud Misconfig9.1Critical25
V-038MongoDB no auth internet exposed—cloud-mongodbCLOUDDB9.8Critical25
V-052Scholarship portal SQLi—scholarship-portalDMZInjection9.1Critical25
V-067Placement file upload RCE—placement-webDMZRCE9.8Critical25
V-097Proctoring server file upload RCE—proctoring-serverDMZRCE9.8Critical25
V-101Hostel allotment SQLi—hostel-allotmentDMZInjection9.1Critical25
V-002Nginx 1.14 EOL unpatchedCVE-2019-20372hostel-web02DMZWeb Server7.5High20
V-004IDOR on /v1/students/{id}—api-gwDMZAPI/AuthZ8.6High20
V-005SQL Injection in portal login—student-portal-dbCOREInjection9.8Critical20
V-007ERP default admin creds—erp-appCOREAuth9Critical20
V-008SMBv1/NTLM relay possibleCVE-2017-0144ad-ldapCORENetwork9.3Critical20
V-010Public SSH password auth—cloudvm-reportsCLOUDNetwork7High20
V-016No rate limiting on login—api-gwDMZAPI/Brute7.5High20
V-021GitLab CE RCE outdatedCVE-2021-22205git-serverCORERCE9.9Critical20
V-022Jenkins unauth script console—ci-runnerCORERCE9.8Critical20
V-023Hikvision NVR auth bypassCVE-2021-36260cctv-nvrCOREIoT9.8Critical20
V-024vCenter 6.7 RCE unauthCVE-2021-21972vcenterCORERCE9.8Critical20
V-025Payroll DB sa default password—payroll-dbCOREAuth9Critical20
V-026Legacy MySQL 5.5 multiple CVEs—legacy-student-dbCOREDB9.1Critical20
V-027JWT none algorithm accepted—api-gwDMZAPI/Auth8.6High20
V-035Exchange ProxyLogonCVE-2021-26855exchange-serverCORERCE9.8Critical20
V-036Exchange ProxyShell chainCVE-2021-34473exchange-serverCORERCE9.8Critical20
V-039Elasticsearch no auth exposed—elk-elasticsearchCOREDB9.1Critical20
V-040Docker API exposed 2375—docker-host-01CORERCE9.8Critical20
V-041Kubernetes dashboard no auth—k8s-masterCOREMisconfig9.1Critical20
V-044Confluence OGNL injection RCECVE-2021-26084confluenceCORERCE9.8Critical20
V-046Win Server 2008 EOL unsupported—legacy-erpCOREOS EOL9.8Critical20
V-047SMBv1 enabled Server 2003CVE-2017-0144legacy-fileserverCORENetwork9.3Critical20
V-048Oracle 11g multiple known CVEs—legacy-oracle-dbCOREDB9Critical20
V-049Moodle SQLi in enrolmentCVE-2021-32474lms-appDMZInjection8.8High20
V-050Mobile API broken object auth—mobile-api-prodDMZAPI/AuthZ8.6High20
V-051Payment gateway weak TLS 1.0—payment-gateway-intDMZCrypto7.4High20
V-053Medical portal IDOR records—medical-portalDMZAPI/AuthZ8.6High20
V-062Apache 2.4.29 EOL outdatedCVE-2019-0211alumni-portalDMZWeb Server7.8High20
V-065Grievance DB SQLi via API—grievance-dbCOREInjection9.1Critical20
V-073BlueKeep RDP RCE possibleCVE-2019-0708jump-hostCORERCE9.8Critical20
V-084Hadoop HDFS web UI exposed—data-lakeCLOUDMisconfig7.5High20
V-085Lambda overprivileged IAM role—cloud-lambda-apiCLOUDCloud Misconfig7.6High20
V-089Staging API debug mode enabled—staging-apiDMZInfo Leak7.5High20
V-091Test portal default creds admin/admin—test-portalDMZAuth8.8High20
V-094DR domain controller unpatchedCVE-2020-1472dr-site-controllerDRAuth10Critical20
V-095Zerologon Netlogon priv escCVE-2020-1472ad-ldapCOREAuth10Critical20
V-098Mobile API JWT secret weak—mobile-api-prodDMZAPI/Auth8.1High20
V-099Push service SSRF internal scan—mobile-push-svcDMZSSRF7.7High20
V-100Result service IDOR view marks—result-publish-svcDMZAPI/AuthZ8.6High20
V-108Windows 7 EOL lab PCs—lab-pc-01COREOS EOL9.8Critical20
V-109Windows 7 SMB EternalBlueCVE-2017-0144lab-pc-02CORERCE9.3Critical20
V-006Reflected XSS in search param—portal-web01DMZXSS6.1Medium12
V-009Open SMB share anon read—backup-nasCOREMisconfig8.1High12
V-012Tomcat manager weak creds—attendance-srvCOREAuth8.8High12
V-013Verbose error stack trace leak—api-gwDMZInfo Leak5.3Medium12
V-014Missing security headers—portal-web01DMZConfig4.3Medium12
V-015Cleartext internal traffic—student-portal-dbCORECrypto7.4High12
V-017Hardcoded API key in kiosk fw—face-kiosk-01CORESecrets8.2High12
V-018MS SQL xp_cmdshell enabled—erp-dbCOREDB8.8High12
V-028Kerberoastable service accounts—ad-ldapCOREAuth8.1High12
V-029GPP cpassword in SYSVOL—fileserver-01CORESecrets8.1High12
V-030Payroll IDOR payslips—payroll-appCOREAPI/AuthZ8.6High12
V-031ESXi OpenSLP heap overflow RCECVE-2021-21974esxi-host-01CORERCE8.8High12
V-032ESXi unpatched same as host-01CVE-2021-21974esxi-host-02CORERCE8.8High12
V-034AD CS ESC1 misconfiguration—ca-serverCOREAuth8.8High12
V-043OpenSSH 7.6 user enumerationCVE-2018-15473sftp-serverDMZNetwork5.3Medium12
V-054Medical DB weak credentials—medical-dbCOREAuth8.1High12
V-055Grievance portal stored XSS—grievance-webDMZXSS6.1Medium12
V-056Wallet server logic flaw negative balance—wallet-serverCOREBusiness Logic8.2High12
V-057Wallet DB cleartext PINs—wallet-dbCORECrypto8.1High12
V-058Biometric server unencrypted templates—biometric-serverCORECrypto8.6High12
V-059Door access controller default creds—door-access-ctrlCOREAuth8High12
V-060MQTT broker no authentication—iot-gatewayCOREIoT7.5High12
V-063Helpdesk app reflected XSS—helpdesk-appDMZXSS6.1Medium12
V-064Helpdesk DB weak credentials—helpdesk-dbCOREAuth7.5High12
V-066Placement IIS directory listing—placement-webDMZMisconfig5.3Medium12
V-068Hostel DB exposed to all VLANs—hostel-dbCORENetwork7.4High12
V-069Attendance DB default postgres pw—attendance-dbCOREAuth8.1High12
V-072Jump host RDP NLA disabled—jump-hostCORENetwork7.5High12
V-074Server 2012R2 SMB signing disabled—fileserver-02CORENetwork7.5High12
V-075PrintNightmare spooler RCECVE-2021-34527print-serverCORERCE8.8High12
V-077BIND 9.11 cache poisoningCVE-2021-25220dns-serverDMZNetwork6.8Medium12
V-078WLC outdated mgmt over HTTP—wifi-controllerCORECrypto7.4High12
V-079Core switch default SNMP public—switch-core-01COREMisconfig7.5High12
V-080Edge router SSH weak ciphers—router-edgeDMZCrypto5.9Medium12
V-081Internal FW permissive any-any rule—firewall-internalCOREMisconfig8.1High12
V-082Cloud RDS publicly accessible—cloud-rdsCLOUDCloud Misconfig8.6High12
V-083ElastiCache Redis no auth—cloud-elasticacheCLOUDDB7.5High12
V-086Nexus repo unauth artifact read—nexus-repoCOREMisconfig7.5High12
V-087Artifactory anonymous access—artifactoryCOREMisconfig7.5High12
V-088Dev DB prod data copy exposed—dev-dbCOREData Exposure8.6High12
V-090Dev portal source map exposed—dev-portalDMZInfo Leak5.3Medium12
V-092Veeam backup RCE deserializationCVE-2022-26500tape-backup-srvCORERCE8.8High12
V-093Backup credentials stored cleartext—tape-backup-srvCORESecrets8.1High12
V-096Moodle outdated XSS in forum—lms-appDMZXSS6.1Medium12
V-102Transport portal open redirect—transport-portalDMZMisconfig4.7Medium12
V-104Library DB SQLi search—library-dbCOREInjection8.8High12
V-105Roundcube webmail stored XSSCVE-2020-12640webmailDMZXSS6.1Medium12
V-106Skype for Business EOL—skype-serverCOREOS EOL7.5High12
V-110Canteen POS hardcoded DB string—canteen-posCORESecrets7.5High12
V-042Vault sealed-state info leak—vault-secretsCOREInfo Leak5.3Medium6
V-045Jira unauth user enumerationCVE-2020-14181jira-serverCOREInfo Leak5.3Medium6
V-061HVAC BACnet exposed unauth—hvac-controllerCOREIoT6.5Medium6
V-070Keycloak outdated SSRFCVE-2020-10770sso-idpCORESSRF6.5Medium6
V-071Keycloak open redirect—sso-idpCOREMisconfig5.4Medium6
V-076DNS zone transfer allowed—dns-internal-01COREMisconfig5.3Medium6
V-103Research grants app CSRF—research-grants-appCORECSRF6.5Medium6
V-107Terminal server weak RDP encryption—terminal-serverCORECrypto5.9Medium6