Findings
Vulnerabilities
All findings with CVSS, mapped host, and Likelihood × Impact risk score.
110
Total findings
36
Critical
28
With known CVE
42
On public assets
110 of 110
Severity
Zone
Exposure
| ID | Finding | CVE | Host | Zone | Category | CVSS | Severity | Risk▼ |
|---|---|---|---|---|---|---|---|---|
| V-001 | Apache 2.4.41 path traversal | CVE-2021-41773 | portal-web01 | DMZ | Web Server | 9.8 | Critical | 25 |
| V-003 | API missing auth on /v1/students | — | api-gw | DMZ | API/Auth | 9.1 | Critical | 25 |
| V-011 | FortiOS SSL-VPN path traversal | CVE-2018-13379 | vpn-gw | DMZ | VPN | 9.8 | Critical | 25 |
| V-019 | Apache mod_cgi RCE | CVE-2021-41773 | library-web | DMZ | Web Server | 9.8 | Critical | 25 |
| V-020 | Exam portal SQLi in id param | — | exam-portal | DMZ | Injection | 9.1 | Critical | 25 |
| V-033 | PAN-OS GlobalProtect RCE | CVE-2024-3400 | firewall-perimeter | DMZ | Firewall | 10 | Critical | 25 |
| V-037 | S3 bucket public write access | — | s3-bucket-backups | CLOUD | Cloud Misconfig | 9.1 | Critical | 25 |
| V-038 | MongoDB no auth internet exposed | — | cloud-mongodb | CLOUD | DB | 9.8 | Critical | 25 |
| V-052 | Scholarship portal SQLi | — | scholarship-portal | DMZ | Injection | 9.1 | Critical | 25 |
| V-067 | Placement file upload RCE | — | placement-web | DMZ | RCE | 9.8 | Critical | 25 |
| V-097 | Proctoring server file upload RCE | — | proctoring-server | DMZ | RCE | 9.8 | Critical | 25 |
| V-101 | Hostel allotment SQLi | — | hostel-allotment | DMZ | Injection | 9.1 | Critical | 25 |
| V-002 | Nginx 1.14 EOL unpatched | CVE-2019-20372 | hostel-web02 | DMZ | Web Server | 7.5 | High | 20 |
| V-004 | IDOR on /v1/students/{id} | — | api-gw | DMZ | API/AuthZ | 8.6 | High | 20 |
| V-005 | SQL Injection in portal login | — | student-portal-db | CORE | Injection | 9.8 | Critical | 20 |
| V-007 | ERP default admin creds | — | erp-app | CORE | Auth | 9 | Critical | 20 |
| V-008 | SMBv1/NTLM relay possible | CVE-2017-0144 | ad-ldap | CORE | Network | 9.3 | Critical | 20 |
| V-010 | Public SSH password auth | — | cloudvm-reports | CLOUD | Network | 7 | High | 20 |
| V-016 | No rate limiting on login | — | api-gw | DMZ | API/Brute | 7.5 | High | 20 |
| V-021 | GitLab CE RCE outdated | CVE-2021-22205 | git-server | CORE | RCE | 9.9 | Critical | 20 |
| V-022 | Jenkins unauth script console | — | ci-runner | CORE | RCE | 9.8 | Critical | 20 |
| V-023 | Hikvision NVR auth bypass | CVE-2021-36260 | cctv-nvr | CORE | IoT | 9.8 | Critical | 20 |
| V-024 | vCenter 6.7 RCE unauth | CVE-2021-21972 | vcenter | CORE | RCE | 9.8 | Critical | 20 |
| V-025 | Payroll DB sa default password | — | payroll-db | CORE | Auth | 9 | Critical | 20 |
| V-026 | Legacy MySQL 5.5 multiple CVEs | — | legacy-student-db | CORE | DB | 9.1 | Critical | 20 |
| V-027 | JWT none algorithm accepted | — | api-gw | DMZ | API/Auth | 8.6 | High | 20 |
| V-035 | Exchange ProxyLogon | CVE-2021-26855 | exchange-server | CORE | RCE | 9.8 | Critical | 20 |
| V-036 | Exchange ProxyShell chain | CVE-2021-34473 | exchange-server | CORE | RCE | 9.8 | Critical | 20 |
| V-039 | Elasticsearch no auth exposed | — | elk-elasticsearch | CORE | DB | 9.1 | Critical | 20 |
| V-040 | Docker API exposed 2375 | — | docker-host-01 | CORE | RCE | 9.8 | Critical | 20 |
| V-041 | Kubernetes dashboard no auth | — | k8s-master | CORE | Misconfig | 9.1 | Critical | 20 |
| V-044 | Confluence OGNL injection RCE | CVE-2021-26084 | confluence | CORE | RCE | 9.8 | Critical | 20 |
| V-046 | Win Server 2008 EOL unsupported | — | legacy-erp | CORE | OS EOL | 9.8 | Critical | 20 |
| V-047 | SMBv1 enabled Server 2003 | CVE-2017-0144 | legacy-fileserver | CORE | Network | 9.3 | Critical | 20 |
| V-048 | Oracle 11g multiple known CVEs | — | legacy-oracle-db | CORE | DB | 9 | Critical | 20 |
| V-049 | Moodle SQLi in enrolment | CVE-2021-32474 | lms-app | DMZ | Injection | 8.8 | High | 20 |
| V-050 | Mobile API broken object auth | — | mobile-api-prod | DMZ | API/AuthZ | 8.6 | High | 20 |
| V-051 | Payment gateway weak TLS 1.0 | — | payment-gateway-int | DMZ | Crypto | 7.4 | High | 20 |
| V-053 | Medical portal IDOR records | — | medical-portal | DMZ | API/AuthZ | 8.6 | High | 20 |
| V-062 | Apache 2.4.29 EOL outdated | CVE-2019-0211 | alumni-portal | DMZ | Web Server | 7.8 | High | 20 |
| V-065 | Grievance DB SQLi via API | — | grievance-db | CORE | Injection | 9.1 | Critical | 20 |
| V-073 | BlueKeep RDP RCE possible | CVE-2019-0708 | jump-host | CORE | RCE | 9.8 | Critical | 20 |
| V-084 | Hadoop HDFS web UI exposed | — | data-lake | CLOUD | Misconfig | 7.5 | High | 20 |
| V-085 | Lambda overprivileged IAM role | — | cloud-lambda-api | CLOUD | Cloud Misconfig | 7.6 | High | 20 |
| V-089 | Staging API debug mode enabled | — | staging-api | DMZ | Info Leak | 7.5 | High | 20 |
| V-091 | Test portal default creds admin/admin | — | test-portal | DMZ | Auth | 8.8 | High | 20 |
| V-094 | DR domain controller unpatched | CVE-2020-1472 | dr-site-controller | DR | Auth | 10 | Critical | 20 |
| V-095 | Zerologon Netlogon priv esc | CVE-2020-1472 | ad-ldap | CORE | Auth | 10 | Critical | 20 |
| V-098 | Mobile API JWT secret weak | — | mobile-api-prod | DMZ | API/Auth | 8.1 | High | 20 |
| V-099 | Push service SSRF internal scan | — | mobile-push-svc | DMZ | SSRF | 7.7 | High | 20 |
| V-100 | Result service IDOR view marks | — | result-publish-svc | DMZ | API/AuthZ | 8.6 | High | 20 |
| V-108 | Windows 7 EOL lab PCs | — | lab-pc-01 | CORE | OS EOL | 9.8 | Critical | 20 |
| V-109 | Windows 7 SMB EternalBlue | CVE-2017-0144 | lab-pc-02 | CORE | RCE | 9.3 | Critical | 20 |
| V-006 | Reflected XSS in search param | — | portal-web01 | DMZ | XSS | 6.1 | Medium | 12 |
| V-009 | Open SMB share anon read | — | backup-nas | CORE | Misconfig | 8.1 | High | 12 |
| V-012 | Tomcat manager weak creds | — | attendance-srv | CORE | Auth | 8.8 | High | 12 |
| V-013 | Verbose error stack trace leak | — | api-gw | DMZ | Info Leak | 5.3 | Medium | 12 |
| V-014 | Missing security headers | — | portal-web01 | DMZ | Config | 4.3 | Medium | 12 |
| V-015 | Cleartext internal traffic | — | student-portal-db | CORE | Crypto | 7.4 | High | 12 |
| V-017 | Hardcoded API key in kiosk fw | — | face-kiosk-01 | CORE | Secrets | 8.2 | High | 12 |
| V-018 | MS SQL xp_cmdshell enabled | — | erp-db | CORE | DB | 8.8 | High | 12 |
| V-028 | Kerberoastable service accounts | — | ad-ldap | CORE | Auth | 8.1 | High | 12 |
| V-029 | GPP cpassword in SYSVOL | — | fileserver-01 | CORE | Secrets | 8.1 | High | 12 |
| V-030 | Payroll IDOR payslips | — | payroll-app | CORE | API/AuthZ | 8.6 | High | 12 |
| V-031 | ESXi OpenSLP heap overflow RCE | CVE-2021-21974 | esxi-host-01 | CORE | RCE | 8.8 | High | 12 |
| V-032 | ESXi unpatched same as host-01 | CVE-2021-21974 | esxi-host-02 | CORE | RCE | 8.8 | High | 12 |
| V-034 | AD CS ESC1 misconfiguration | — | ca-server | CORE | Auth | 8.8 | High | 12 |
| V-043 | OpenSSH 7.6 user enumeration | CVE-2018-15473 | sftp-server | DMZ | Network | 5.3 | Medium | 12 |
| V-054 | Medical DB weak credentials | — | medical-db | CORE | Auth | 8.1 | High | 12 |
| V-055 | Grievance portal stored XSS | — | grievance-web | DMZ | XSS | 6.1 | Medium | 12 |
| V-056 | Wallet server logic flaw negative balance | — | wallet-server | CORE | Business Logic | 8.2 | High | 12 |
| V-057 | Wallet DB cleartext PINs | — | wallet-db | CORE | Crypto | 8.1 | High | 12 |
| V-058 | Biometric server unencrypted templates | — | biometric-server | CORE | Crypto | 8.6 | High | 12 |
| V-059 | Door access controller default creds | — | door-access-ctrl | CORE | Auth | 8 | High | 12 |
| V-060 | MQTT broker no authentication | — | iot-gateway | CORE | IoT | 7.5 | High | 12 |
| V-063 | Helpdesk app reflected XSS | — | helpdesk-app | DMZ | XSS | 6.1 | Medium | 12 |
| V-064 | Helpdesk DB weak credentials | — | helpdesk-db | CORE | Auth | 7.5 | High | 12 |
| V-066 | Placement IIS directory listing | — | placement-web | DMZ | Misconfig | 5.3 | Medium | 12 |
| V-068 | Hostel DB exposed to all VLANs | — | hostel-db | CORE | Network | 7.4 | High | 12 |
| V-069 | Attendance DB default postgres pw | — | attendance-db | CORE | Auth | 8.1 | High | 12 |
| V-072 | Jump host RDP NLA disabled | — | jump-host | CORE | Network | 7.5 | High | 12 |
| V-074 | Server 2012R2 SMB signing disabled | — | fileserver-02 | CORE | Network | 7.5 | High | 12 |
| V-075 | PrintNightmare spooler RCE | CVE-2021-34527 | print-server | CORE | RCE | 8.8 | High | 12 |
| V-077 | BIND 9.11 cache poisoning | CVE-2021-25220 | dns-server | DMZ | Network | 6.8 | Medium | 12 |
| V-078 | WLC outdated mgmt over HTTP | — | wifi-controller | CORE | Crypto | 7.4 | High | 12 |
| V-079 | Core switch default SNMP public | — | switch-core-01 | CORE | Misconfig | 7.5 | High | 12 |
| V-080 | Edge router SSH weak ciphers | — | router-edge | DMZ | Crypto | 5.9 | Medium | 12 |
| V-081 | Internal FW permissive any-any rule | — | firewall-internal | CORE | Misconfig | 8.1 | High | 12 |
| V-082 | Cloud RDS publicly accessible | — | cloud-rds | CLOUD | Cloud Misconfig | 8.6 | High | 12 |
| V-083 | ElastiCache Redis no auth | — | cloud-elasticache | CLOUD | DB | 7.5 | High | 12 |
| V-086 | Nexus repo unauth artifact read | — | nexus-repo | CORE | Misconfig | 7.5 | High | 12 |
| V-087 | Artifactory anonymous access | — | artifactory | CORE | Misconfig | 7.5 | High | 12 |
| V-088 | Dev DB prod data copy exposed | — | dev-db | CORE | Data Exposure | 8.6 | High | 12 |
| V-090 | Dev portal source map exposed | — | dev-portal | DMZ | Info Leak | 5.3 | Medium | 12 |
| V-092 | Veeam backup RCE deserialization | CVE-2022-26500 | tape-backup-srv | CORE | RCE | 8.8 | High | 12 |
| V-093 | Backup credentials stored cleartext | — | tape-backup-srv | CORE | Secrets | 8.1 | High | 12 |
| V-096 | Moodle outdated XSS in forum | — | lms-app | DMZ | XSS | 6.1 | Medium | 12 |
| V-102 | Transport portal open redirect | — | transport-portal | DMZ | Misconfig | 4.7 | Medium | 12 |
| V-104 | Library DB SQLi search | — | library-db | CORE | Injection | 8.8 | High | 12 |
| V-105 | Roundcube webmail stored XSS | CVE-2020-12640 | webmail | DMZ | XSS | 6.1 | Medium | 12 |
| V-106 | Skype for Business EOL | — | skype-server | CORE | OS EOL | 7.5 | High | 12 |
| V-110 | Canteen POS hardcoded DB string | — | canteen-pos | CORE | Secrets | 7.5 | High | 12 |
| V-042 | Vault sealed-state info leak | — | vault-secrets | CORE | Info Leak | 5.3 | Medium | 6 |
| V-045 | Jira unauth user enumeration | CVE-2020-14181 | jira-server | CORE | Info Leak | 5.3 | Medium | 6 |
| V-061 | HVAC BACnet exposed unauth | — | hvac-controller | CORE | IoT | 6.5 | Medium | 6 |
| V-070 | Keycloak outdated SSRF | CVE-2020-10770 | sso-idp | CORE | SSRF | 6.5 | Medium | 6 |
| V-071 | Keycloak open redirect | — | sso-idp | CORE | Misconfig | 5.4 | Medium | 6 |
| V-076 | DNS zone transfer allowed | — | dns-internal-01 | CORE | Misconfig | 5.3 | Medium | 6 |
| V-103 | Research grants app CSRF | — | research-grants-app | CORE | CSRF | 6.5 | Medium | 6 |
| V-107 | Terminal server weak RDP encryption | — | terminal-server | CORE | Crypto | 5.9 | Medium | 6 |