Network Vulnerability Scanners
Network vulnerability scanners probe TCP/UDP services for misconfigurations, weak protocols, and known CVEs. Essential for mapping your external attack surface and validating firewall rules.
Important Network Vulnerabilities Scanners
SMB ms17-010 - EternalBlue Vulnerability Scanner
The SMBv1 server allows remote attackers to execute arbitrary code via crafted packets, aka "Windows SMB Remote Code Execution Vulnerability."
Microsoft RDP Vulnerability (MS12-020) Scanner
You can scan your machine to detect RDP vulnerability by using this tool.
FTP Bounce Checker
FTP bounce attack is a vulnerability type where an attacker who cannot access a server in the internal network by using targeted FTP server as a proxy to transfer files and scans ports. If this explanation sounds complex, don’t worry. You can check whether your server is impacted by this vulnerability by using our tool.
SSH V1 Vulnerability Scanner
Learn whether your SSH server supports less secure SSHv1 protocol. Check this vulnerability and configure your SSH server to support SSHv2.
Misconfigured Redis Scanner
Online Misconfigured Redis Scanner
Basic uPNP Device Scanner
A misconfigured authentication vulnerability is a type of vulnerability that is most commonly found to affect the devices like modems, routers, digital cameras, printers, uPNP devices, servers or web-based configuration or administrative interfaces having no password to access all configuration settings.
DarkTrackRAT Trojan RAT Detection Scanner
Identify the stealthy DarkTrack RAT Trojan within your network. Ensure proactive defense and protection against unauthorized remote access and control.
ZTE Router Backdoor Detection Scanner
Identify the stealthy backdoor within your network. This scanner detects the presence of backdoors in ZTE Router Panels that could potentially lead to unauthorized access and exploitation. Ensure your network remains secure from these hidden threats.
DarkComet Trojan RAT Detection Scanner
Identify the stealthy DarkComet Trojan within your network. Detect and mitigate potential threats associated with this malicious remote access tool. Ensure your systems remain secure by effectively identifying this RAT.
XtremeRAT Trojan RAT Detection Scanner
Identify the stealthy XtremeRAT Trojan within your network. This scanner is invaluable for detecting the presence of this Remote Access Trojan, known for targeting sensitive networks. Ensure your cybersecurity measures include this tool to prevent data breaches and unauthorized access.
7777-Botnet C2 Detection Scanner
Identify the stealthy 7777-Botnet or C2 within your network. Detect potential threats related to command and control communication, enhancing your network security.
Apache Tomcat WebSocket Frame Payload Length Validation Denial of Service Scanner
Detects 'Denial of Service (DoS)' vulnerability in Apache Tomcat affects v. 10.0.0-M1 to 10.0.0-M6, 9.0.0.M1 to 9.0.36, 8.5.0 to 8.5.56, 7.0.27 to 7.0.104. This vulnerability can cause high CPU usage through malformed WebSocket frames.
Open Redirect Bypass Detection Scanner
This scanner detects the presence of open redirect vulnerabilities in digital assets. Open redirection can lead to phishing attacks or other malicious redirections.
Misconfigured Kibana/Elasticsearch Scanner
Online Misconfigured Kibana/Elasticsearch Scanner
TCP Config Information Disclosure Scanner
An attacker gets critical informations from TCP config page.
Windows Services List via SNMP Vulnerability Scanner
You can get information about Win32 SNMP services.
Voldemort Native Protocol Vulnerability Scanner
You can scan Voldemort distributed key-value store using this tool.
LDAP Root DSA-specific Entry (DSE) Scanner
LDAP Root DSA-specific Entry (DSE) Scanner
Titan FTP Server 6.05 DELE Command - Heap Overflow
Titan FTP Server version 6.05 build 550 contains a heap overflow vulnerability when processing long DELE commands. Remote attackers can cause denial of service (daemon crash) or potentially execute arbitrary code by sending excessively long arguments to the DELE command.
SonicWall SMA1000 WorkPlace - Unauthenticated SSRF to CouchDB
A Pre-authentication SSRF vulnerability exists in the SMA1000 Appliance Work Place interface due to an unintended alternate access path.
SonicWall SMA1000 - Server-Side Request Forgery
SMA1000 Appliance Work Place interface contains a server side request forgery caused by improper request validation, letting remote unauthenticated attackers make requests to unintended locations, exploit requires no special privileges.
Fortinet FortiSIEM - OS Command Injection
FortiSIEM versions 6.4.0 through 7.1.1 contain an OS command injection vulnerability in the Phoenix Monitor service. The vulnerability exists in the XML parsing of TEST_STORAGE elements where the mount_point field is not properly sanitized before being passed to shell commands, allowing unauthenticated remote code execution.
FortiManager Unauthenticated Remote Code Execution
A missing authentication vulnerability in Fortinet FortiManager allows a remote unauthenticated attacker to execute arbitrary code or commands via specially crafted requests to the fgfmd daemon. This vulnerability affects FortiManager versions 7.6.0, 7.4.0 through 7.4.4, 7.2.0 through 7.2.7, 7.0.0 through 7.0.12, 6.4.0 through 6.4.14, 6.2.0 through 6.2.12, and all versions of 6.0.
VMware ESXi SLP - Heap Overflow DoS
OpenSLP as used in ESXi and the Horizon DaaS appliances has a heap overwrite issue. VMware has evaluated the severity of this issue to be in the Critical severity range with a maximum CVSSv3 base score of 9.8.
NCR Command Center Agent 16.3 - Remote Command Execution
CMCAgent in NCR Command Center Agent 16.3 on Aloha POS/BOH servers permits the submission of a runCommand parameter (within an XML document sent to port 8089) that enables the remote, unauthenticated execution of an arbitrary command as SYSTEM, as exploited in the wild in 2020 and/or 2021. NOTE: the vendor's position is that exploitation occurs only on devices with a certain "misconfiguration."
CVE-2017-7494 Scanner
Detects 'Remote Code Execution (RCE)' vulnerability in Samba affects v. 3.5.0 and before 4.6.4, 4.5.10 and 4.4.14.
Unix Command Injection - Generic Detection
Detected potential Unix/Linux OS command injection by replacing query parameter values with shell separator payloads and identifying successful command execution through command output patterns or response time delays. Payloads included semicolons, pipes, logical AND operators, backticks, command substitution, and newline injection.
Oracle WebLogic Server - Remote Code Execution (Insecure Deserialization)
Oracle WebLogic Server 12.2.1.3.0, 12.2.1.4.0, and 14.1.1.0.0 contain a remote code execution caused by unauthenticated network access via IIOP and T3, letting attackers take over the server, exploit requires network access.
Fortinet FortiSIEM - OS Command Injection
Fortinet FortiSIEM 6.7.9
Oracle WebLogic Server - Remote Code Execution
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 10.3.6.0.0, 12.1.3.0.0, 12.2.1.3.0 and 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via IIOP, T3 to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in takeover of Oracle WebLogic Server. CVSS 3.0 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).
CrushFTP - Authentication Bypass Race Condition
CrushFTP 10 before 10.8.5 and 11 before 11.3.4_23, when the DMZ proxy feature is not used, mishandles AS2 validation and consequently allows remote attackers to obtain admin access via HTTPS, as exploited in the wild in July 2025.
Samba Printing Subsystem - Remote Code Execution
A flaw was found in the Samba printing subsystem. Samba passes the client-controlled job description string to the command configured with the "print command" setting via the "%J" substitution character without escaping shell meta characters. A remote attacker could exploit this vulnerability by sending a specially crafted print job description that contains unescaped shell characters. This could lead to remote code execution on the affected system.
Fortinet SSL-VPN - Heap-Based Buffer Overflow
A heap-based buffer overflow vulnerability [CWE-122] in FortiOS SSL-VPN (versions 7.2.0 through 7.2.2, 7.0.0 through 7.0.8, 6.4.0 through 6.4.10, 6.2.0 through 6.2.11, 6.0.15 and earlier) and FortiProxy SSL-VPN (versions 7.2.0 through 7.2.1, 7.0.7 and earlier) may allow a remote unauthenticated attacker to execute arbitrary code or commands via specifically crafted requests.
Windows Command Injection - Generic Detection
Detected potential OS command injection on Windows targets by replacing query parameter values with command separator payloads and identifying successful command execution through output patterns from `dir`, `whoami`, `systeminfo`, or response time delays induced via `ping`.
Apache RocketMQ - Remote Command Execution
The RocketMQ NameServer component still has a remote command execution vulnerability as the CVE-2023-33246 issue was not completely fixed in version 5.1.1. When NameServer address are leaked on the extranet and lack permission verification, an attacker can exploit this vulnerability by using the update configuration function on the NameServer component to execute commands as the system users that RocketMQ is running as. It is recommended for users to upgrade their NameServer version to 5.1.2 or above for RocketMQ 5.x or 4.9.7 or above for RocketMQ 4.x to prevent these attacks.
Spring Framework RCE via Data Binding on JDK 9+
A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data binding. The specific exploit requires the application to run on Tomcat as a WAR deployment. If the application is deployed as a Spring Boot executable jar, i.e. the default, it is not vulnerable to the exploit. However, the nature of the vulnerability is more general, and there may be other ways to exploit it.
ProFTPD mod_sql - Preauth User Backdoor
ProFTPD mod_sql before 1.3.10rc1 contains a remote code execution caused by unsafe username handling with SQL backend commands in USER request logging expansions, letting remote attackers execute arbitrary code, exploit requires SQL backend allowing commands.
RustFS < 1.0.0-alpha.77 - Hardcoded gRPC Authentication Token
RustFS before 1.0.0-alpha.77 used a hardcoded gRPC authentication token "rustfs rpc" that could not be changed without recompiling and this allowed unauthenticated remote attackers to gain full administrative access to the gRPC API.
Fortinet FortiSIEM - Unauthenticated Command Injection
An improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiSIEM versions 7.1.0 through 7.1.1, 7.0.0 through 7.0.2, 6.7.0 through 6.7.8, 6.6.0 through 6.6.3, 6.5.0 through 6.5.2, and 6.4.0 through 6.4.3 allows an unauthenticated attacker to execute unauthorized code or commands via crafted API requests.
WatchGuard IKEv2 Out-of-Bounds Write Vulnerability
WatchGuard Fireware OS 11.10.2 to 11.12.4_Update1, 12.0 to 12.11.3, and 2025.1 contains an out-of-bounds write caused by improper handling in Mobile User VPN and Branch Office VPN with IKEv2 dynamic gateway peer, letting remote unauthenticated attackers execute arbitrary code.
Titan FTP Server 6.03 and 6.0.5.549 - Heap Overflow via Long Commands
Titan FTP Server versions 6.03 and 6.05 (builds) contain multiple heap-based buffer overflow vulnerabilities. Remote attackers can cause denial of service (daemon crash) or potentially execute arbitrary code by sending excessively long USER, PASS, or other FTP commands that trigger heap overflows.
Marimo <= 0.20.4 - Pre-Auth Terminal WebSocket RCE
Marimo versions
BeyondTrust Remote Support - Unauthenticated WebSocket RCE
BeyondTrust Remote Support is vulnerable to unauthenticated remote code execution via the WebSocket endpoint /nw. An attacker can extract the company identifier from the /get_mech_list endpoint and use it to connect to the WebSocket service, then inject OS commands through the binary WebSocket payload that are executed on the server.
NTPsec > 1.1.3 - 'ctl_getitem' Out-of-Bounds Read
NTPsec before 1.1.3 contains a stack-based buffer over-read caused by a bug in ctl_getitem in read_sysvars in ntp_control.c in ntpd, letting local or remote attackers read sensitive memory, exploit requires sending crafted control requests.
Palo Alto Networks PAN-OS - Authentication Bypass
Palo Alto Networks PAN-OS contains an authentication bypass caused by flaws in the GlobalProtect portal and gateway, letting attackers establish unauthorized VPN connections, exploit requires network access to the portal or gateway.
BMC FootPrints - Deserialization of Untrusted Data (RCE)
BMC FootPrints Asset Core is vulnerable to pre-authentication remote code execution via Java deserialization in the aspnetconfig endpoint.
Ivanti Connect Secure - Stack-based Buffer Overflow
Ivanti Connect Secure before version 22.7R2.6, Ivanti Policy Secure before version 22.7R1.4, and Ivanti ZTA Gateways before version 22.8R2.2 contain a stack-based buffer overflow caused by improper input handling, allowing remote attackers to execute arbitrary code without authentication.
Apache Log4j2 - Remote Code Injection
Apache Log4j2 Thread Context Lookup Pattern is vulnerable to remote code execution in certain non-default configurations.
Zimbra Collaboration Suite < 10.1.20 - OS Command Injection
Zimbra Collaboration Suite (ZCS) before version 10.1.20 is vulnerable to OS command injection in the SNMP notification processing due to improper input sanitization. According to the NVD, when SNMP notifications are enabled and the zimbra-snmp package is installed, an unauthenticated attacker can inject arbitrary commands using crafted SMTP requests that result in malicious log entries. The swatchdog service monitors the log, and upon matching a pattern, passes the log content to zmsnmptrapd, which unsafely uses the Perl backtick operator to execute commands. This can ultimately allow remote attackers to execute arbitrary operating system commands as the zimbra user. Active exploitation of this vulnerability has been observed in the wild, as confirmed by CERT Polska and CISA.
HP Switch - Authentication Bypass
A potential security vulnerability has been identified in Hewlett Packard Enterprise OfficeConnect 1820, 1850, and 1920S Network switches. The vulnerability could be remotely exploited to allow authentication bypass. HPE has made the following software updates to resolve the vulnerability in Hewlett Packard Enterprise OfficeConnect 1820, 1850 and 1920S Network switches versions- Prior to PT.02.14; Prior to PC.01.22; Prior to PO.01.21; Prior to PD.02.22;
TitanFTP move-file Function 1.94.1205 - Path Traversal
TitanFTP versions up to 1.94.1205 contain a path traversal vulnerability in the move-file function where the newPath parameter is improperly validated. An authenticated user can upload a file and then move it to any location on the server filesystem, potentially allowing arbitrary file placement and system compromise.
Next.js WebSocket Upgrade Handler - SSRF
Next.js 13.4.13 to before 15.5.16 and 16.2.5 contains a server-side request forgery caused by crafted WebSocket upgrade requests in the built-in Node.js server, letting attackers proxy requests to arbitrary destinations, exploit requires self-hosted deployment.
Pure-FTPd < 1.0.52 - Buffer Overflow
Pure-FTPd versions prior to 1.0.52 contain a buffer overflow vulnerability due to an out-of-bounds read in the domlsd() function within the ls.c file. This vulnerability could allow attackers to execute arbitrary code on affected systems.
Veritas Backup Exec - Broken Authentication
An issue was discovered in Veritas Backup Exec before 21.2. It supports multiple authentication schemes- SHA authentication is one of these. This authentication scheme is no longer used in current versions of the product, but hadn't yet been disabled. An attacker could remotely exploit this scheme to gain unauthorized access to an Agent and execute privileged commands.
Vite Dev Server - Arbitrary File Read
Vite dev server exposes the fetchModule method via its WebSocket HMR (Hot Module Replacement) endpoint using the vite-hmr sub-protocol. By connecting to the WebSocket endpoint and sending a crafted vite:invoke custom event that calls fetchModule with a file:// URL (e.g., file:///etc/passwd?raw), an attacker can bypass server.fs.deny restrictions and read arbitrary files from the server filesystem. The vulnerability exists because fetchModule does not enforce the same filesystem access controls as other Vite server endpoints.
Tornado - Out of Band Template Injection
Tornado - Out of Band Template Injection
CVE-2021-35394 Scanner
CVE-2021-35394 Scanner - Remote Code Execution (RCE) vulnerability in RealTek AP Router SDK
Orcus RAT Trojan RAT Detection Scanner
Identify the stealthy Orcus RAT Trojan within your network. Detect unauthorized Remote Administration Tool usage to prevent potential data breaches and ensure network security.
Smarty - Server Side Template Injection
In PHP template engine Smarty, template injection is possible by exploiting the passthru function combined with array_map and chr.
Thymeleaf - Out of Band Template Injection
Thymeleaf template injection occurs when user input is embedded in a template without proper sanitization. This can lead to remote code execution through Thymeleaf's expression language features.
Run all Network Vulnerabilities checks at once.
S4E covers 259+ scanners in this category with continuous monitoring and full remediation guidance.
Start Free Scan →