
Introducing Apex Discovery to secure every domain you actually own
Most tools will only test the domains you already know about. We’ve decided that’s not enough. TLDR: Detectify’s new Apex Discovery automatically identifies root domains …

Our Crowdsource ethical hacker community has been busy sending us security updates, including 0-day research. For Asset Monitoring, we now push out tests more frequently at record speed within 25 minutes from hacker to scanner. Due to confidentially agreements, we cannot publicize all security update releases here but they are immediately added to our scanner and available to all users.
The following are some of the security vulnerabilities reported by Detectify Crowdsource ethical hackers. We added these tests to the Detectify scanner in the last weeks:
This module looks for a macro injection vulnerability SolarWinds Serv-U before 15.2.2. An unauthenticated attacker can get critical information on the target including encrypted credentials from the configuration (SMTP, LDAP) and cleartext credentials of any connected user, thus leading to RCE.
This module searches for an unauthenticated arbitrary nonce generation vulnerability in Redirection for Contact Form 7 prior to versions 2.3.3. Attackers could use this nonce generation vulnerability to exploit other vulnerabilities.
This module will try to bypass the AEM dispatcher to list all packages. After that, an attacker can download packages. An unauthenticated attacker will be able to download package which may contain sensitive data.
This module looks for a reflected XSS vulnerability in Concrete5 CMS before version 8.5.2. An attacker can use this flaw to steal credentials and otherwise execute JavaScript in the origin of the affected domain.
This module tries to find Panabit consoles using default credentials for admin authentication. An attacker will be able to authenticate to Panabit and gain privileges to the service.
This module looks for a remote code execution vulnerability in VoIPmanager before version 24.61. An attacker can execute arbitrary code on the server.

Most tools will only test the domains you already know about. We’ve decided that’s not enough. TLDR: Detectify’s new Apex Discovery automatically identifies root domains …

We are launching the Detectify MCP Server to deliver real-time vulnerability data and attack surface insights directly into your AI-powered workflows. Built for developers and …