Sign in

LeakIX

@leakix.bsky.social
91 followers 2 following 42 posts

Maintaining and reporting for LeakIX. We are NOT affiliated with any ransomware campaign. mastodon.social/@leakix

PostsRepliesMedia
LeakIX @leakix.bsky.social · 09/03/2026
LeakIX is now available as a Metasploit module. Search, host lookups, subdomains, and leaks directly from msfconsole. github.com/rapid7/metasploit-framew…
picture
010
LeakIX @leakix.bsky.social · 02/01/2026
🚨 Plugin update: ZimbraPlugin (CVE-2025-68645). Zimbra Collaboration Suite 10.0 and 10.1 affected by unauthenticated LFI vulnerability. Results: leakix.net/search?q=%2Btags%3Acve-2…
picture
000
LeakIX @leakix.bsky.social · 02/01/2026
🚨 New plugin: SmarterMailPlugin (CVE-2025-52691). SmarterMail versions prior to Build 9413 affected by critical remote code execution vulnerability via arbitrary file upload. Results: leakix.net/search?q=%2Bplugin%3ASma…
picture
000
LeakIX @leakix.bsky.social · 30/12/2025
🚨 New plugin: MongoBleedPlugin (CVE-2025-14847). MongoDB Memory Leak vulnerability detection. Results: leakix.net/search?page=0&q=%2Bplugi…
picture
000
LeakIX @leakix.bsky.social · 26/12/2025
🚨 New plugin: N8nPlugin (CVE-2025-68613, CVE-2025-65964, CVE-2025-62726). n8n Workflow Automation multiple vulnerabilities detection. Results: leakix.net/search?q=%2Bplugin%3AN8n…
picture
000
LeakIX @leakix.bsky.social · 12/12/2025
🚨 New plugin: GeoserverXxePlugin (CVE-2025-58360). GeoServer XXE vulnerability detection - XML External Entity injection in WMS GetMap operation, added to CISA KEV catalog. Results: leakix.net/search?q=%2Bplugin%3AGeo…
picture
000
LeakIX @leakix.bsky.social · 09/12/2025
🚨 Plugin update: React2ShellPlugin (CVE-2025-55182). Backdoor detection added - 16k+ Next.js servers detected with in-memory webshells allowing remote code execution. Results: leakix.net/search?scope=leak&q=%2Bp…
picture
010
LeakIX @leakix.bsky.social · 05/12/2025
🚨 New plugin: React2ShellPlugin (CVE-2025-55182). React Server Components RCE vulnerability detection - Next.js applications affected by critical remote code execution vulnerabilities. Results: leakix.net/search?page=0&q=%2Bplugi…
picture
000
LeakIX @leakix.bsky.social · 05/12/2025
🚨 New plugin: EzGED3Plugin (CVE-2025-51539). EzGED3 pre-authentication arbitrary file read vulnerability detection - may lead to admin takeover. Results: leakix.net/search?q=%2Bplugin%3AEzG…
picture
000
LeakIX @leakix.bsky.social · 04/12/2025
🚨 New plugin: FreePBXPlugin (CVE-2025-57819). FreePBX unauthenticated SQL injection vulnerability detection - may lead to RCE. Results: leakix.net/search?q=%2Bplugin%3AFre…
picture
010
LeakIX @leakix.bsky.social · 03/12/2025
🚨 New plugin: TraccarPlugin (CVE-2025-61666). Traccar local file inclusion vulnerability detection - may expose configuration files. Results: leakix.net/search?q=%2Bplugin%3ATra…
picture
000
LeakIX @leakix.bsky.social · 02/12/2025
🚨 New plugin: KestrelPlugin (CVE-2025-55315). Kestrel HTTP request smuggling vulnerability detection. Results: leakix.net/search?q=%2Bplugin%3AKes…
picture
010
LeakIX @leakix.bsky.social · 01/12/2025
🚨 New plugin: XWikiPlugin (CVE-2025-24893, CVE-2025-32429, CVE-2025-52472, CVE-2025-55748). XWiki multiple critical vulnerabilities detection - RCE, SQL/HQL injection, and path traversal. Results: leakix.net/search?q=%2Bplugin%3AXWi…
picture
010
LeakIX @leakix.bsky.social · 27/11/2025
🚨 New plugin: FlowiseVersionPlugin. Flowise vulnerability detection - detects 15+ CVEs including RCE, file upload, and SSRF vulnerabilities. Results: leakix.net/search?q=%2Bplugin%3AFlo…
picture
000
LeakIX @leakix.bsky.social · 26/11/2025
🚨 New plugin: WazuhPlugin (CVE-2025-24016). Wazuh default credentials and RCE vulnerability detection - RCE possible on multi-node configurations, versions 4.4.0 to 4.9.1 affected. Results: leakix.net/search?q=%2Bplugin%3AWaz…
picture
000
LeakIX @leakix.bsky.social · 25/11/2025
🚨 New plugin: ICTBroadcastRcePlugin (CVE-2025-2611). ICTBroadcast unauthenticated RCE vulnerability detection. Results: leakix.net/search?q=%2Bplugin%3AICT…
picture
000
LeakIX @leakix.bsky.social · 24/11/2025
🚨 New plugin: SpipRcePlugin (CVE-2024-8517). SPIP BigUp plugin pre-authentication RCE vulnerability detection. Results: leakix.net/search?q=%2Bplugin%3ASpi…
picture
000
LeakIX @leakix.bsky.social · 21/11/2025
🚨 New plugin: ViciboxVersionPlugin (CVE-2024-8503, CVE-2024-8504). VICIdial outdated version detection - unauthenticated SQL injection and authenticated RCE, versions <= 2.14-917a affected. Results: leakix.net/search?q=%2Bplugin%3AVic…
picture
000
LeakIX @leakix.bsky.social · 20/11/2025
🚨 New plugin: NCentralPlugin (CVE-2025-9316, CVE-2025-11700). N-able N-Central session bypass and XXE vulnerability detection - XXE allows reading critical files. Results: leakix.net/search?q=%2Bplugin%3ANCe…
picture
000
LeakIX @leakix.bsky.social · 20/11/2025
🚨 New plugin: MagentoXxePlugin (CVE-2024-34102, CosmicSting). Magento XXE injection vulnerability detection - may expose sensitive files, RCE possible in some cases. Results: leakix.net/search?q=%2Bplugin%3AMag…
picture
000
LeakIX @leakix.bsky.social · 19/11/2025
🚨 Plugin update: PaloAltoPlugin (CVE-2024-3400, CVE-2025-0133). PaloAlto PAN-OS XSS vulnerability detection added - GlobalProtect portal affected. Results: leakix.net/search?q=%2Bplugin%3APal…
picture
000
LeakIX @leakix.bsky.social · 18/11/2025
🚨 New plugin: GeoserverRcePlugin (CVE-2024-36401). GeoServer RCE vulnerability detection via GetPropertyValue in WFS requests. Results: leakix.net/search?q=%2Bplugin%3AGeo…
picture
000
LeakIX @leakix.bsky.social · 17/11/2025
🚨 New plugin: SwaggerUIPlugin. Swagger API documentation public exposure detection - may expose API endpoints, parameters, and data structures. Results: leakix.net/search?q=%2Bplugin%3ASwa…
picture
000
LeakIX @leakix.bsky.social · 14/11/2025
🚨 New plugin: PrometheusPlugin. Prometheus server public exposure detection - may expose metrics, configuration, and infrastructure information. Results: leakix.net/search?q=%2Bplugin%3APro…
picture
000
LeakIX @leakix.bsky.social · 13/11/2025
🚨 New plugin: GraphQLIntrospectionPlugin. GraphQL introspection enabled detection - may expose sensitive schema information and database structures. Results: leakix.net/search?q=%2Bplugin%3AGra…
picture
000
LeakIX @leakix.bsky.social · 12/11/2025
🚨 New plugin: WatchGuardFireboxPlugin (CVE-2025-59396). WatchGuard Firebox default credentials allow administrative SSH access. CVE rejected by NVD: "Not a security vulnerability". Results: leakix.net/search?q=%2Bplugin%3AWat…
picture
000
LeakIX @leakix.bsky.social · 12/11/2025
🚨 New plugin: GladinetPlugin (CVE-2025-11371, CVE-2025-30406, CVE-2025-12480). Gladinet CentreStack/Triofox LFI, RCE, and auth bypass vulnerability detection. Results: leakix.net/search?q=%2Bplugin%3AGla…
picture
000
LeakIX @leakix.bsky.social · 12/11/2025
🚨 New plugin: GLPIVersionPlugin. GLPI vulnerability detection - detects 50+ CVEs including unauthenticated SQL injection, session hijacking, and account takeover. Results: leakix.net/search?q=%2Bplugin%3AGLP…
picture
000
LeakIX @leakix.bsky.social · 07/11/2025
🚨 New plugin: MonstaFtpVersionPlugin (CVE-2025-34299). MonstaFTP RCE vulnerability detection - versions < 2.11.3 affected. Results: leakix.net/search?scope=leak&q=%2Bp…
picture
000
LeakIX @leakix.bsky.social · 22/10/2025
🚨 New plugin: SessionReaperPlugin (CVE-2025-54236) added. Multiple Adobe Commerce / Magento instances exposed. Patch ASAP. Details: slcyber.io/assetnote-security-resea… Query: +plugin:SessionReaperPlugin
picture
000
LeakIX @leakix.bsky.social · 08/10/2025
🚨 New plugin for Oracle E-Business Suite's CVE-2025-61882 is up. First huge plugin by Chocapikk 🥳 LeakIX now has OOB scanning capability! The check based on actual vulnerability evaluation ( as opposed to Last-Modified fingerprinting that can be unreliable ).
picturepicture
010
LeakIX @leakix.bsky.social · 11/04/2025
🚨 New plugin for ViteJS's CVE-2025-30208 is up. It's dev, nothing wrong can happen right? Have fun. Source: x.com/phithon_xg/status/19053517325…
image
000
LeakIX @leakix.bsky.social · 11/04/2025
🚨 New plugin for CrushFTP's CVE-2025-2825/CVE-2025-31161 is up. While enumerating users to validate vulnerable instances we noticed a pattern. It's on all instances we scanned for, can you see it? What do you make of it?
image
000
LeakIX @leakix.bsky.social · 07/03/2025
🚨 Detection for Cisco ASA CVE-2020-3259 has been added. ~2.5k vulnerable instances still found on a 5 years old vulnerability allowing for session hijacking and credentials stealing. Source: cyberplace.social/@GossiTheDog/1118… Query: +plugin:CiscoASAPlugin
image
000
LeakIX @leakix.bsky.social · 14/01/2025
🚨 Detection for Kerio Control's CVE-2024-52875 has been added. ~500 vulnerable instances have been found. Hosting providers & CERTs have been notified, patch now! Credits: karmainsecurity.com/hacking-kerio-c… Query: +plugin:KerioControlPlugin
image
000
LeakIX @leakix.bsky.social · 10/01/2025
💡No #opendir? Why don't you check for .DS_Store files listing the structure ? Our scans found 11,856,006 IPs and DNS exposing the file. Link: leakix.net/search?scope=leak&q=%2Bp… Ref: 0day.work/parsing-the-ds_store-file…
image
000
LeakIX @leakix.bsky.social · 07/01/2025
⚠️ During our scans we found ~70K applications exposing their VSCode SFTP config. These are often critical and can include FTP/SSH credentials. You can check this out here: leakix.net/search?q=%2Bplugin%3AVsC… #cybersecurity #vscode #vulnerability
image
000
LeakIX @leakix.bsky.social · 03/01/2025
💡 Have you checked our 3rd party Docker registry scan plugin? Eg, looking for images names aimed at production environments: +plugin:DockerRegistryHttpPlugin And as a reminder, we have a Docker Registry Exploration tool at github.com/leakIX/dre.
image
020
LeakIX @leakix.bsky.social · 17/12/2024
🚨 New pro plugin is in! We are now looking for mis-configured Spring Boot actuators and indexing metadata to help with research! Query: +plugin:"SpringBootActuatorPlugin" Thanks: @Chocapikk_ for the idea! Credits: www.wiz.io/blog/spring-...
000
LeakIX @leakix.bsky.social · 06/12/2024
🚨 Detection for Mitel MiCollab's CVE-2024-35286 and CVE-2024-41713 has been added. ~2000 vulnerable instances have been found. Hosting providers & CERTs have been notified, patch now! Credits: @watchtowrcyber Thanks: @Chocapikk_
011
LeakIX @leakix.bsky.social · 04/12/2024
Let's see if there's anyone up on this service :)
010
LeakIX @leakix.bsky.social · 04/12/2024
🚨This a yearly reminder to check for PHP information pages where sensitive environment variables could be shared. More than 800K affected services on LeakIX. 👇👇👇 Example: Leaked Azure database credentials and authentication signing key.
153