34 open · 8 critical
Thirty-four findings. Eight that actually matter.
Every finding arrives ranked, de-duplicated and backed by a reproducible path — what it is, what it reaches, how to reproduce it, and the fix, routed to the owner. Not a four-hundred-page export for somebody to triage by hand.
8CriticalCVSS 9–10
9High
6In a proven chain
12Remediatedretested
Operator is retesting — verifying 3 recent remediations
High & critical findings
| CVSS | CVE | Vulnerability | Asset | Status |
|---|---|---|---|---|
| 10.0 | CVE-2021-44228 | Apache Log4j2 RCE “Log4Shell” KEVIn chain | jenkins-ci.acme.sa | Validated |
| 10.0 | CVE-2017-5638 | Apache Struts2 content-type RCE KEV | apps-legacy.acme.sa | Found |
| 9.8 | CVE-2023-34362 | MOVEit Transfer SQLi → RCE KEV | filetransfer.acme.sa | Awaiting approval |
| 9.8 | CVE-2021-34473 | MS Exchange “ProxyShell” KEV | autodiscover.acme.sa | Found |
| 9.8 | CVE-2019-0708 | RDP “BlueKeep” pre-auth RCE KEV | ts-old.acme.sa | Found |
| 9.8 | CVE-2022-26134 | Atlassian Confluence OGNL RCE KEVIn chain | wiki-2019.acme.sa | In chain |
| 9.4 | CVE-2023-4966 | Citrix NetScaler “Citrix Bleed” KEVWeaponized | vpn-old.acme.sa | Validated |
| 7.5 | CVE-2014-3704 | Drupal “Drupalgeddon” SQLi KEV | news-cms.acme.sa | Found |
Findings by severity
Critical8
High9
Medium10
Low7
Coverage by layer
Recon & surface98%
Web & app logic84%
Identity & access72%
Cloud posture68%
AI / LLM systems45%