Metabase SQL Injection Check (CVE-2026-72898)
Flags Metabase by version for CVE-2026-72898 SQL injection, then confirms with a sleep probe. CISA KEV.
loading
This collection was built fully autonomously by AI. Every detector was researched from public CVE data, generated, and validated end to end with no human authoring. Detection fingerprints and flags by version first, then runs a non-intrusive confirm (sleep, public file, or unauthenticated GET). No exploitation. Beta: newly generated and still being refined.
Drop 1 is 21 CISA KEV checks. Point them at your own hosts. Each fingerprints the product, flags by version, then runs a non-intrusive confirm: sleep, public-file read, or unauthenticated GET.
Flags Metabase by version for CVE-2026-72898 SQL injection, then confirms with a sleep probe. CISA KEV.
Flags LoadMaster by version for CVE-2026-8037 command injection, then confirms with an unauthenticated GET. CISA KEV.
Flags N-central by version for CVE-2026-18577 authentication bypass, then confirms with an unauthenticated GET. CISA KEV.
Flags FortiOS by version for CVE-2025-68686 information disclosure, then confirms with an unauthenticated GET. CISA KEV.
Flags UniFi OS by version for CVE-2026-34909 path traversal, then confirms with a public-file read. CISA KEV.
Flags PAN-OS GlobalProtect by version for CVE-2026-0257 authentication bypass, then confirms with an unauthenticated GET. CISA KEV.
Flags LiteLLM by version for CVE-2026-42208 SQL injection, then confirms with a sleep probe. CISA KEV.
Flags ScreenConnect by version for CVE-2024-1708 path traversal, then confirms with a public-file read. CISA KEV.
Flags TeamCity by version for CVE-2024-27199 authentication bypass, then confirms with an unauthenticated GET. CISA KEV.
Flags Langflow by version for CVE-2026-33017 code injection, then confirms with a sleep probe. CISA KEV.
Flags BeyondTrust RS/PRA by version for CVE-2026-1731 command injection, then confirms with a sleep probe. CISA KEV.
Flags FortiAnalyzer and FortiManager by version for CVE-2026-24858 authentication bypass, then confirms with an unauthenticated GET. CISA KEV.
Flags SmarterMail by version for CVE-2026-23760 authentication bypass, then confirms with an unauthenticated GET. CISA KEV.
Flags Grafana by version for CVE-2021-43798 path traversal, then confirms with a public-file read. CISA KEV.
Flags NetWeaver by version for CVE-2017-12637 path traversal, then confirms with a public-file read. CISA KEV.
Flags Jira Server and Data Center by version for CVE-2021-26086 path traversal, then confirms with a public-file read. CISA KEV.
Flags vCenter by version for CVE-2022-22948 information disclosure, then confirms with an unauthenticated GET. CISA KEV.
Flags Check Point Quantum by version for CVE-2024-24919 information disclosure, then confirms with a public-file read. CISA KEV.
Flags BIG-IP Configuration Utility by version for CVE-2023-46748 SQL injection, then confirms with a sleep probe. CISA KEV.
Flags Openfire by version for CVE-2023-32315 path traversal, then confirms with an unauthenticated GET. CISA KEV.
Flags MOVEit Transfer by version for CVE-2023-34362 SQL injection, then confirms with a sleep probe. CISA KEV.