Why did you scan me?
When you landed on this page, it is probably because you witnessed one of our scanners in you logs. We operate the following scanners:
- AS50559 - IPv4: 194.5.73.0/24 aka 194.5.73.0-194.5.73.255 - Our own local infrastructure
Don’t Panic
You have been scanned by the non-profit Dutch Institute for Vulnerability Disclosure (DIVD; Twitter: @divdnl). We scan the internet to detect systems that potentially contain vulnerabilities to inform system owners. All to support our mission:
We only test systems if our tests pass the criteria of proportionality and subsidiarity, which means that our tests are non-intrusive and as light-weight as possible and that there are no other ways to reach the same effect.
Additionally, all our research and our researchers are bound by our code of conduct.
DIVD does not operate on an opt-in or opt-out basis, but you can block the scanners above, although we highly recommend against it.
We currently have the following cases open, so the scan you observed is likely related to one of them:
- DIVD-2025-00035 - Sharepoint Mass-Exploitation (ToolShell) through CVE-2025-53770
- DIVD-2025-00034 - Remote Code Execution in IBM WebSphere version 8.5 and 9.0
- DIVD-2025-00033 - Remote Code Execution in GeoServer versions below 2.27.0, 2.26.2 and 2.25.6
- DIVD-2025-00032 - Unauthenticated Arbitrary Remote Code Execution in Pterodactyl
- DIVD-2025-00031 - Critical vulnerabilities in Citrix ADC and Gateway systems
- DIVD-2025-00018 - Victim Notification Operation Endgame 2.0
- DIVD-2025-00012 - Four vulnerabilities in Schneider Electric EVLink Wallbox
- DIVD-2025-00011 - Failed authentication check in Growatt portal
- DIVD-2025-00009 - Sungrow’s iSolarCloud MQTT lacking permissions
- DIVD-2025-00006 - Next.js Middleware Authorization Bypass
- DIVD-2025-00005 - Exposed Automated Tank Gauge Systems
- DIVD-2025-00003 - Multiple vulnerabilities in Mennekes Smart / Premium Charging stations
- DIVD-2025-00001 - Multiple vulnerabilities in Sicomm BASEC Service
- DIVD-2024-00051 - Improper authorization vulnerabilty in ProjectSend,
- DIVD-2024-00035 - 17 vulnerabilities in Iocharger devices
- DIVD-2024-00019 - Victim Notification Operation Endgame
- DIVD-2024-00011 - Six vulnerabilities in Enphase IQ Gateway devices