漏洞描述 Detects a publicly accessible HashiCorp Vault API instance that is unsealed and responding without authentication. This critical misconfiguration can expose sensitive secrets and enable privilege escalation or lateral movement.
相关漏洞推荐 POC wp-security-hidden-login-exposure: WordPress All-in-One Security <=4.4.1 - Hidden Login Page Exposure POC CVE-2025-11749: WordPress AI Engine Plugin - Token Exposure POC cockroachdb-unauth-exposure: CockroachDB Unauthenticated Console Exposure POC CVE-2025-55190: ArgoCD Project API Token Repository Credentials Exposure POC CVE-2025-9985: Featured Image from URL (FIFU) <= 5.2.7 - Unauthenticated Information Exposure via Log File POC churchcrm-installer: ChurchCRM - Setup Exposure Commvault /commandcenter/publicLink.do 权限绕过漏洞(CVE-2025-57788) alertmanager-unauth: Alertmanager 未授权访问 druid-monitor-unauth: Druid Monitor Unauth etcd-unauth: ETCD Unauth springboot-actuator-unauth: Springboot Actuator Unauth docker-registry-api-unauth: docker registry api 未经批准 wanhu-evointerfaceservlet-unauth: 万户 OA 未授权访问获取所有账户密码