AI vositalari qoldirgan xavfsizlik teshiklarini toping.
Free instant scan. Finds exposed Supabase service keys, missing RLS, open Firebase rules, leaked secrets in your JS bundle, and more.
- No signup required
- 400+ checks performed
- BaaS-aware
- Auth-safe (passive)
Scanner coverage
- 70+
- vulnerability classes covered
- 250+
- passive checks / scan
- 100+
- active checks / scan
- 50+
- GitHub checks / scan
Mos keladi
AI coding tools bilan yaratilgan websites va apps-ni scan qiling.
Cursor, Claude Code, Codex, Lovable, Bolt, v0, Replit va boshqa tools orqali deploy qilganingizda, FixVibe live URL va repo-ni tekshiradi, AI-generated apps ko‘pincha o‘tkazib yuboradigan security gaps-ni topadi.
- Cursor
- Claude Code
- OpenAI Codex
- GitHub Copilot
- Lovable
- Bolt.new
- v0
- Replit Agent
- Windsurf
- Devin
- Google Jules
- Gemini CLI
- Firebase Studio
- Amazon Q Developer
- JetBrains Junie
- Kiro
- Tabnine
- Qodo
- Sourcegraph Amp
- Continue
- Cline
- Roo Code
- Aider
- OpenCode
- Base44
- Anything
- Builder.io Fusion
- Tempo
- Softgen
- Trae
En son araştırma
Yangi vulnerabilities, har kuni.
We track newly disclosed CVEs, GHSA advisories, and BaaS misconfiguration patterns that matter to AI-built apps. Public notes explain impact and safe remediation at a high level.
- criticalcovered by FixVibe
Ghost kontentda SQL injection API (CVE-2026-26980)
3.24.0 dan 6.19.0 gacha bo'lgan Ghost versiyalari API Kontentida muhim SQL in'ektsiya zaifligini o'z ichiga oladi. Bu autentifikatsiya qilinmagan tajovuzkorlarga o'zboshimchalik bilan SQL buyruqlarini bajarishga imkon beradi, bu esa ma'lumotlarning eksfiltratsiyasiga yoki ruxsatsiz o'zgartirishlarga olib kelishi mumkin.
- highcovered by FixVibe
Andoza teglari (CVE-2016-7998) orqali SPIP da masofaviy kodni bajarish
SPIP 3.1.2 va undan oldingi versiyalarida shablonni yaratuvchisida zaiflik mavjud. Tasdiqlangan tajovuzkorlar serverda ixtiyoriy PHP kodini bajarish uchun yaratilgan INCLUDE yoki INCLURE teglari bilan HTML fayllarni yuklashlari mumkin.
- highcovered by FixVibe
ZoneMinder Apache konfiguratsiyasi ma'lumotlarini oshkor qilish (CVE-2016-10140)
ZoneMinder 1.29 va 1.30 versiyalari to'plamdagi Apache HTTP Server noto'g'ri konfiguratsiyasidan ta'sirlangan. Ushbu kamchilik masofaviy, autentifikatsiya qilinmagan tajovuzkorlarga veb-ildiz katalogini ko'rib chiqish imkonini beradi, bu esa maxfiy ma'lumotlarni oshkor qilish va autentifikatsiyani chetlab o'tishga olib keladi.
Current research, practical context, and coverage updates when checks ship.
Barcha research →