ShadowTrackr

Log in >
RSS feed

New detections, and false positive CVE removed

12 January 2026
The current update has more and better software detections, focussing mostly on webframeworks and remote login services.

Recently all vulnerabilities detected on certificates where included in the main vulnerability index. Some of you have noticed that CVE-2013-0169 (LUCKY13) appeared on quite a few webserver/certificates. You can prevent this by removing all CBC ciphers, but the truth is that about all webservers have fixed this vulnerability years ago and almost all instances where CVE-2013-0169 is found are false positives.

CVE-2013-0169 is now marked as false positive and does not appear in the vulnerability index anymore. It does still show on the certificate page with the notice that the webserver presenting the certificate is possibly vulnerable.
Older posts >

Resources
API
Blog
Documentation
Integrations
Shodan
OpenCTI