<?xml version="1.0" encoding="UTF-8"?><urlset xmlns="http://www.sitemaps.org/schemas/sitemap/0.9" xmlns:news="http://www.google.com/schemas/sitemap-news/0.9" xmlns:xhtml="http://www.w3.org/1999/xhtml" xmlns:image="http://www.google.com/schemas/sitemap-image/1.1" xmlns:video="http://www.google.com/schemas/sitemap-video/1.1"><url><loc>https://www.memcyber.com/</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>1.0</priority></url><url><loc>https://www.memcyber.com/about</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>monthly</changefreq><priority>0.6</priority></url><url><loc>https://www.memcyber.com/ai-policy</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>monthly</changefreq><priority>0.6</priority></url><url><loc>https://www.memcyber.com/changelog</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>monthly</changefreq><priority>0.6</priority></url><url><loc>https://www.memcyber.com/clients</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/clients/african-fintech-neobank</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/clients/defi-lending-protocol</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/clients/european-sportsbook</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/clients/move-l1-protocol</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/clients/saas-compliance-platform</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/clients/sea-investment-app</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/contact</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>monthly</changefreq><priority>0.9</priority></url><url><loc>https://www.memcyber.com/disclosures</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/2fa-bypass-grants-full-dashboard-without-verification-step</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/2fa-token-brute-force-no-rate-limiting</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/3-admin-source-maps-publicly-accessible-17-9mb-source</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/5-aws-s3-buckets-including-cdn-user-photo</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/5x-redacted-database-instances-fully-accessible-critical-mega</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/8-internal-services-publicly-accessible-including-grafana-and-admin</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/16-guest-order-endpoints-with-zero-authentication</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/16-spring-boot-actuator-endpoints-exposed-on-8-domains</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/17-1mb-source-map-exposes-complete-admin-dashboard-source</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/18-production-backend-microservices-exposed</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/21-6-gb-public-debug-log-exposes-payment-credentials-and-server-paths</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/22-26-scopes-granted-with-empty-client-secret</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/23mb-source-map-application-code-exposure-2752-files</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/30-production-microservices-publicly-accessible</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/86-public-pusher-trade-channels-front-running</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/168-gaming-platform-credentials-exposed-via-public-endpoint</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/180-admin-api-endpoints-exposed-via-source-map</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/512-bit-rsa-key-for-login-encryption-redacted-ially-factorable</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/adl-safety-mechanism-neutralized-via-trivial-repayment-in-emode-group</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/admin-account-takeover-via-otp-brute-force</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/admin-authentication-bypass-via-telegram-parameter-13-endpoints</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/admin-backoffice-open-registration</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/admin-console-delete-users-id-missing-admin-role-check-user-deletion</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/admin-control-tower-source-map-exposure-123-files</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/admin-dashboard-publicly-accessible-with-full-route-exposure</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/admin-graphql-updatetransaction-createmanualbatch-schema-exposure</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/admin-js-leaks-120-api-endpoints-including-kyc-and-bybit-auto-sell</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/admin-login-approval-status-idor-unauthenticated-monitoring-high</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/admin-panel-30-admin-api-endpoints-fully-open</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/admin-panel-publicly-accessible-with-dev-tools-enabled-high</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/admin-panel-publicly-accessible-with-full-frontend-source</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/admin-panel-source-code-exposure-via-source-map</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/admin-panel-source-map-exposed</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/admin-panel-source-map-exposure-555-files</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/admin-panel-swagger-api-docs-kyc-microservice-exposure</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/admin-panel-zero-server-side-authentication</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/admin-panels-publicly-accessible</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/admin-staging-panel-exposed</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/admin-user-hashes-exposed-via-getadmins</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/admin-viewdetail-accepts-leaked-twofatoken-as-auth</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/adminjs-database-admin-panel-publicly-reachable</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/adminswapcurrencies-bfla-financial-theft</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/advertisement-idor-reveals-170k-ads-without-auth</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/aes-decryption-key-hardcoded-in-admin-source-map</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/aes-encryption-secret-key-exposed-client-side-crypto-broken</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/african-fintech-mass-scan</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/airsign-microservice-unauth-registration-ed25519-key</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/airtable-api-key-with-create-permissions-on-7-bases</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/akamai-mpulse-origin-ip-bypass</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/alibaba-cloud-oss-bucket-public-read-confirmed</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/amplitude-api-write-access-enables-event-injection</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/apexmetanew-firestore-storage-open</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/api-authorization-keys-hardcoded-in-javascript</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/api-cors-wildcard-mass-assignment-on-registration-critical</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/api-signature-without-server-secret-on-9-brand-apis</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/app-link-wrappers-with-nested-link-parameter-bypass-origin-control</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/apple-oauth-csrf-via-static-apple-state-parameter</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/arbitrary-file-write-via-fileoutputstream-deserialization</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/arbitrary-live-api-key-creation-without-password-confirmation</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/argocd-production-unauthenticated-settings-exposure</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/argocd-v2-14-8-settings-leak-with-execenabled-true</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/asp-net-dev-api-stack-trace-source-code-path-disclosure</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/ato-chain-verified</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/ato-via-otp-brute-force-no-rate-limit</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/auth-middleware-bypass-on-crypto-withdrawal-endpoint</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/auth0-open-registration-enables-unlimited-account-creation</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/authentication-bypass-on-consumer-financing-order-endpoints</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/aux00-internal-django-dashboard-login-exposed</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/avalanche-rpc-cors-wildcard-with-credentials</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/aws-elasticache-internal-ip-leaked-via-actuator</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/aws-s3-configuration-files-publicly-accessible</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/azure-ad-tenant-client-id-leak</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/b-lslb-api-unauthenticated-business-data-exposure-78-production-records</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/back-office-oauth-registration-bypass-2-33m-transaction-data-breach</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/backup-prioritas-admin-panel-full-source-code-exposure</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/bani-payment-webhook-inverted-signature-verification</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/bcrypt-password-hash-leaked-in-registration-response-and-jwt-token</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/bfla-on-180-admin-mutations-via-user-jwt</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/billing-invoice-abuse-via-mark-as-paid-without-real-payment</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/blind-ssrf-internal-network-discovery-via-timing-oracle</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/blind-ssrf-into-internal-kubernetes-services</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/blind-xxe-via-altenar-xml-k8s-token-file-exfiltration</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/braze-sdk-api-key-and-multiple-third-party-credentials-exposed</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/bridge-fee-quoted-from-user-supplied-slippage-minimum</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/broken-access-control-on-all-content-apis</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/btc-wallet-abuse-payplus-apexmetanew-virtual-card-theft</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/bugsnag-and-datadog-client-tokens-in-source-map</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/bull-board-job-queue-metrics-unauthenticated</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/business-logic-flaw-cancelled-purchase-re-marked-as-paid</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/bvn-agents-backoffice-frontoffice-swagger-ui-publicly-accessible</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/c-pep-aml-service-openapi-spec-endpoint-disclosure-production</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/cashfree-payment-gateway-secret-key-exposed-in-apk</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/cf-pages-branch-deployments-publicly-accessible</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/change-password-idor-without-authorization-check</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/chatwoot-super-admin-panel-publicly-accessible</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/cleartext-traffic-allowed-to-market-data-servers-in-apk</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/client-auth-otp-bypass-any-code-returns-verified</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/client-bank-account-details-manipulation-via-unprotected-update-api</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/client-registration-credentials-present-in-production-js</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/client-side-password-hashing-with-exposed-salt-pbkdf2-1000</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/cloudflare-turnstile-server-side-validation-missing</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/cloudflare-waf-bypass-via-direct-origin-ip-access</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/cloudflare-waf-complete-bypass-via-origin-ip</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/cloudflare-waf-complete-bypass-via-wageon-origin-ip</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/cnps-production-api-client-auth-bypass</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/codeigniter-3-1-0-backend-exposed-with-user-guide-online</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/complete-admin-panel-api-architecture-exposed-65-endpoints</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/complete-api-authentication-bypass-all-66-endpoints</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/complete-apk-environment-configuration-files-exposed</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/complete-attack-chain-create-forge-validate-free-money</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/complete-environment-config-dump-20-api-keys</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/complete-internal-sdk-extracted-166-endpoints</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/coolify-paas-deployment-panel-publicly-accessible</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/coolify-paas-deployment-platform-publicly-accessible</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/cors-http-downgrade-enables-0-click-crypto-theft-via-mitm</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/cors-misconfiguration-access-control-allow-origin-with-sensitive-data</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/cors-misconfiguration-arbitrary-origin-reflection-with-credentials-criti</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/cors-misconfiguration-on-login-api-enables-credential-theft</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/cors-origin-reflection-credentials-admin-takeover</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/cors-origin-reflection-credentials-enables-full-ato</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/cors-origin-reflection-credentials-full-ato-null-origin</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/cors-origin-reflection-credentials-on-admin-dashboard-api</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/cors-origin-reflection-credentials-on-server-management-panel-critical</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/cors-origin-reflection-credentials-true-on-7-apis-ato-chain</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/cors-origin-reflection-on-24-microservices-dev-production</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/cors-origin-reflection-on-production-api-enables-ato</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/cors-origin-reflection-with-credentials-account-takeover</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/cors-origin-reflection-with-credentials-on-all-928-rest-api-routes</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/cors-origin-reflection-with-credentials-on-backend-services</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/cors-origin-reflection-with-credentials-on-payment-api</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/cors-subdomain-wildcard-trust-with-credentials-on-all-services</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/cors-wildcard-credentials-on-currency-api-vendor</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/cors-wildcard-credentials-true-on-four-api-services</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/cors-wildcard-localstorage-bearer-token-full-cross-origin-account-takeov</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/cors-wildcard-on-23-authenticated-user-order-endpoints-with-delete-metho</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/cors-wildcard-on-all-api-endpoints-enables-cross-origin-account-takeover</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/cors-wildcard-on-api-backend</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/cors-wildcard-on-buffbuff-gaming-gateway</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/cors-wildcard-on-financial-checkout-endpoints-enables-cross-origin-purch</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/cors-wildcard-on-gateway-laravel-auth-header-reflection</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/cors-wildcard-on-v2-api</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/cors-wildcard-with-credentials-on-admin-panel-and-api-critical</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/cors-wildcard-with-credentials-on-production-financial-apis</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/cors-wildcard-with-permissive-headers-on-api</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/critical-60-admin-api-endpoints-exposed</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/critical-367-endpoint-api-specification-exposure-4x-redacted-ui-public</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/critical-admin-panel-source-map-exposure-6-1-mb</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/critical-cors-origin-reflection-credentials-on-graphql-api</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/critical-cors-wildcard-credentials-true</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/critical-cors-wildcard-with-credentials-on-production-api</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/critical-full-stack-trace-disclosure-with-gocd-ci-cd-path-exposure</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/critical-internal-api-documentation-leaks-production-partner-api-archite</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/critical-internal-support-app-full-source-code-exposure-12-8mb-500-files</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/critical-oidc-discovery-exposes-internal-architecture-admin-impersonatio</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/critical-oss-sts-finding</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/critical-supabase-admin-password-exposed-via-unauthenticated-database-ac</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/critical-supabase-hawkvibes-hr-platform-with-48-tables-employee-performa</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/critical-supabase-okr-database-unauthenticated-full-read-access-413-empl</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/critical-unauthenticated-order-status-idor-6-2m-sipariste-mass-enumerati</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/crm-17-unauthenticated-financial-admin-actions</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/crm-admin-panel-publicly-accessible</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/crm-auth-token-generation-formula-exposed</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/crm-sdk-client-id-client-secret-hardcoded-in-apk</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/crypto-deposit-webhook-inverted-checksum-verification</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/crypto-exchange-mass-scan</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/crypto-exchange-scan</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/cryptowallets-idor-exposes-100k-wallet-addresses</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/csrf-protection-bypass-via-hardcoded-fallback-token</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/currency-api-vendor-cors-wildcard-with-credentials</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/cvss-10-0-jwt-forge-tum-merchant-api-erisimi</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/cvss-10-0-prod-postgresql-direkt-erisim-12-veritaban</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/d-redacted-s-extracted-api-endpoints</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/dashboard-redacted-com-dashboard-source-map-exposure-high</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/debug-mode-enabled-on-production-api-endpoints</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/deep-exploitation</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/deep-scan-findings</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/defguard-vpn-panel-exposed-10-vulnerabilities-v1-3-1</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/demo-environment-open-signup-with-full-banking-access</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/deposit-address-hijack-via-addcryptowallet</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/dev-access-token-backdoor-in-source-code</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/dev-environment-public-with-k8s-horizon-endpoints</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/dev-payment-gateway-with-full-fund-transfer-api-publicly-reachable</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/develop-environment-react-app-secret-encryption-key-disclosed</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/developerexceptionpage-enabled-in-production-redeem-cards-com</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/development-and-staging-environments-publicly-accessible</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/development-api-publicly-accessible-in-production</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/digitalocean-spaces-production-credentials-exposed-changera</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/digitalocean-spaces-production-credentials-hardcoded</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/direct-hls-stream-access-without-authentication</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/disable-wp-debug-in-production</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/disclosure-lar</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/disclosure-report</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/dispute-approval-admin-api-without-auth</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/django-admin-panel-exposed-on-production-api</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/django-debug-true-full-settings-dump-with-admin-token</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/django-debug-true-on-production</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/django-debug-true-on-stream-subdomain</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/dms-open-signup-via-google-oauth</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/docker-registry-unauthenticated-full-catalog-access</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/document-upload-and-payment-endpoints-accept-unauthenticated-requests</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/dojah-io-full-application-source-code-via-source-maps</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/druid-sql-monitor-public-on-13-endpoints-across-3-domains</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/eight-dangling-cname-subdomains-target-backend-apis</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/eight-payment-gateway-webhooks-forgeable</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/eleven-unauthenticated-payment-callbacks-pawapay-peach-encryptus-choiceb</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/ema-spot-price-divergence-excess-collateral-seizure-in-lending-liquidati</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/email-enumeration-via-password-reset</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/email-enumeration-via-registration-api</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/email-otp-bypass-via-api-token-enables-unauthorized-withdrawals</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/email-verification-token-brute-force-account-takeover</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/enterprise-api-tokens-exposed-in-public-postman-documentation</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/env-js-config-js-files-expose-internal-service-architecture</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/env-js-production-configuration-leak-high</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/eski-pin-sorulmadi-dogrudan-yeni-pin-set-ediliyor</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/event-registration-pii-mass-dump-659-records</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/evm-webhook-deposit-injection-production</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/exchange-application-full-source-code-via-source-maps</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/exchange-source-maps-reveal-1337-files-and-admin-jwt</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/expo-ota-staging-channel-publicly-accessible</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/exported-push-intent-enables-arbitrary-deep-link-and-webview-routing</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/facebook-apple-social-login-full-account-takeover-no-token-validation</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/fastjson-deserialization-60-dangerous-classes-reachable</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/feature-toggle-bypass-via-query-parameters</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/file-upload-extension-whitelist-bypass-potential</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/final-deep-results</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/firebase-configuration-exposed-with-full-project-details</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/firebase-mass-scan</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/firebase-realtime-database-open-read-write</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/firebase-realtime-database-public-read-access-critical</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/firebase-storage-full-r-w-d-247-303-customer-documents</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/firebase-storage-kyc-document-listing-7-kyc</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/firebase-storage-production-bucket-complete-kyc-data-exposure</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/firebase-storage-public-listing-high</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/firebase-storage-public-read-write-delete-3277-files-exposed</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/firestore-database-74-676-records-with-pii-bvn-exposure</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/firestore-unauthenticated-access</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/fixed-bcrypt-salt-makes-identical-passwords-hash-identically</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/flamberge-auth-less-gcs-bucket-read-write-across-11-buckets</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/flutterwave-secret-key-encryption-key-exposed-in-production-js</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/fonbnk-third-party-callback-forgery-aten-system</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/full-account-takeover-via-password-reset-brute-force-xff-bypass</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/full-admin-source-code-exposure-via-source-maps</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/full-application-source-code-exposure-via-public-source-maps</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/full-application-source-code-exposure-via-source-maps-bitmama</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/full-application-source-code-exposure-via-source-maps</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/full-react-source-code-exposure-via-source-maps-32-1mb-2675-files</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/full-redacted-api-documentation-publicly-exposed-critical</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/full-source-code-exposure-via-source-maps-670-files</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/full-source-code-exposure-via-source-maps-admin-customer</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/full-source-code-exposure-via-source-maps-admin-panel</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/full-source-code-exposure-via-source-maps</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/full-source-code-git-repository-exposure-on-static-site</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/full-source-map-exposure-48-6mb-production-build</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/full-stack-trace-disclosure-in-production-crypto-api</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/fund-theft-chain-via-total-override-mark-as-paid-on-payment-gateway</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/gambling-web3-scan</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/game-tools-api-mass-data-exfiltration-724-business-records-via-idor</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/gcs-bucket-cashiacdn-public-listing-of-14-121-objects</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/gcs-bucket-public-listing-exposes-admin-panel-backup-source-maps</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/generic-webview-fragments-trust-raw-argument-urls</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/genesys-chat-full-exploitation-chain-user-impersonation</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/getalltradelist-unauthenticated-3647-trades-120-plaintext-emails</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/gitlab-open-public-registration</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/gitlab-open-registration-pipeline-trigger-token</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/gke-kubernetes-api-server-publicly-exposed</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/google-2fa-totp-secret-exposed-in-plaintext-via-profile-api</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/google-oauth-client-id-exposed-admin-sso-loopholes</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/google-oauth-client-secret-exposed-in-html</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/google-oauth-client-secret-exposed</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/google-oauth-csrf-via-empty-state-parameter</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/google-oauth-hosted-domain-bypass-potential</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/google-recaptcha-secret-key-exposed-in-frontend</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/grafana-12-0-0-public-metrics-exposes-39-users-and-23-datasources</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/grafana-faro-apm-key-valid-telemetry-injection-verified</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/grafana-metrics-exposes-complete-infrastructure-telemetry</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/grafana-v12-3-0-public-strapi-cms-admin-public</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/graphql-customersearch-returns-pii-wallet-balances-unauth</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/graphql-introspection-cluster-finding</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/growthbook-base-url-override-redacted-code-gb-base-url</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/grpc-reflection-on-all-production-services-200-endpoints</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/guest-order-idor-credential-theft-chain</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/hardcoded-aes-cbc-initialization-vector-across-devices</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/hardcoded-aes-cbc-key-iv-in-mobile-app</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/hardcoded-aes-gcm-production-encryption-key-in-web-bundle</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/hardcoded-aes-key-derivation-salt-shared-across-all-devices</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/hardcoded-aes-key-smartapi2024-full-source-via-source-map</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/hardcoded-api-keys-and-secrets-in-client-side-javascript</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/hardcoded-oauth-client-credentials-in-production-javascript</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/hardcoded-x-privatekey-smartapi-zrzij3bn-used-across-api-calls</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/hashicorp-vault-leaks-internal-k8s-infrastructure-and-oidc</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/hashicorp-vault-staging-unsealed-and-publicly-accessible</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/hashicorp-vault-unsealed-and-publicly-accessible</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/hashicorp-vault-v1-12-1-production-secrets-manager-public</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/helius-mainnet-rpc-key-das-enhanced-api-key</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/hetzner-cloud-metadata-reachable-via-vault-misconfig</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/hidden-admin-dashboard-route-exposed</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/high-acl-email-enumeration-via-login-forgot-password-differential-respon</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/high-admin-dashboard-full-source-code-exposure-via-source-maps</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/high-agent-portal-source-maps-exposed-across-country-instances</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/high-auth-staging-source-map-exposure-5-7mb-348-files-full-auth-logic</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/high-cors-wildcard-on-all-4-imt-backend-apis-367-endpoints-affected</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/high-public-api-documentation-on-target</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/high-redacted-dsn-exposed-event-injection-verified</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/high-sub-merchant-pii-disclosure-via-listsubmerchantpf-vkn-tckn-address</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/high-unauthenticated-currency-data-exposure</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/high-vpn-admin-brute-force-5-valid-employee-emails-zero-rate-limit</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/hmac-api-signing-secret-exposed-in-client-side-js</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/html-email-injection-via-purchase-receipts-enables-phishing</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/http-basic-auth-fallback-with-credentials-in-sessionstorage</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/hyperverge-kyc-sdk-production-credentials-in-apk</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/identityradar-full-source-code-exposure-via-source-map</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/idor-on-user-specific-endpoints-no-ownership-check</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/idor-unauthenticated-bank-account-data-access-via-x-user-id-header</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/infisical-secret-manager-open-registration</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/infura-api-key-exposed-on-minor-exchange</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/insufficient-rate-limiting-on-otp-verification</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/intercom-identity-verification-hmac-secret-exposed-bitmama</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/intercom-identity-verification-hmac-secret-exposed</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/internal-admin-api-publicly-accessible-with-44-grpc-methods</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/internal-admin-redirect-uri-leaked</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/internal-api-documentation-on-public-apidog</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/internal-azure-backend-exposed</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/internal-backend-exposed-on-eight-ports-with-no-firewall</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/internal-production-load-balancer-accessible-from-internet</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/internal-webhooks-accept-negative-amounts-and-race-conditions</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/java-trading-application-jar-publicly-downloadable</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/jenkins-admin-credentials-base64-build-trigger-token</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/jwt-cookie-security-completely-disabled</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/jwt-exploit-results</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/jwt-forgery-idor-full-account-takeover-wallet-access-poc</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/jwt-hs256-weak-secret-exposed-in-apk-cracks-to-plaintext</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/jwt-session-secret-leaked-enables-token-forge</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/jwt-stored-in-localstorage-exposed-to-xss-token-theft</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/jwt-twofatoken-contains-plaintext-admin-password</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/k-1-redacted-setup-token-exposed-critical</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/k-2-vite-development-server-exposed-in-production-critical</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/k-3-transaction-automation-api-with-broken-authentication-critical</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/kafdrop-unauth-full-kafka-access</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/kafka-ui-complete-unauthenticated-access</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/keycloak-25-public-configuration-exposure</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/keycloak-admin-console-publicly-accessible</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/kubernetes-cluster-disclosure-via-unauth-health</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/kubernetes-internal-service-name-leak-via-envoy-headers</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/kubernetes-keda-http-add-on-metadata-exposure-via-headers</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/kyc-api-key-hardcoded-in-android-apk</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/kyc-db-scan</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/kyc-document-bucket-public-access-leaks-user-identity-documents</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/laravel-horizon-dashboard-unauthenticated-full-access</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/laravel-horizon-dashboard-unauthenticated-read-write</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/laravel-ignition-endpoints-active-cve-2021-3129-potential</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/laravel-nova-admin-panel-staging-exposes-65-resource-models</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/laravel-telescope-debug-dashboard-publicly-accessible-on-staging</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/ledger-service-kong-gateway-balance-api-unauthorized-access</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/legal-documents-bucket-public-listing-with-22-user-uuids</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/lenda-app-firestore-open-with-user-data</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/litespeed-webadmin-console-publicly-exposed-high</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/live-api-key-secret-exposed-in-plaintext-via-list-endpoint</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/live-payment-webhook-hijack-to-attacker-controlled-url</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/local-network-arp-audit</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/local-network-mdns-upnp-discovery</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/login-rate-limit-bypass-via-x-forwarded-for-header-spoofing</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/lokalise-api-full-access-translation-manipulation</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/mass-customer-idor-exposes-60-623-users-pii</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/mass-db-scan</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/mass-kyc-file-metadata-exposure-342-files</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/mass-scan-lethal</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/mass-scanner-prompt-v2</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/mass-user-enumeration-reveals-232-800-user-profiles</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/mass-user-pii-exposure-544-users-via-admin-search</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/mass-wallet-address-idor-exposing-600-users-crypto-addresses</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/massive-source-map-exposure-across-3-applications-high</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/me-tr-scan</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/merchant-integration-api-docs-fully-open</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/metabase-analytics-setup-token-exposed-full-internal-config-leak</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/metabase-google-oauth-without-domain-restriction</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/metabase-setup-token-exposed-bi-agrotoken</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/metabase-setup-token-exposed-bi-koywe</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/metabase-setup-token-exposed-bi-tiendacrypto</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/metabase-setup-token-exposed-config-dump</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/metabase-setup-token-exposed-unauth-admin-reprovisioning</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/metabase-setup-token-exposure-bi-vpay-africa</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/metabase-setup-token-exposure</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/metabase-setup-token-leakage-via-api-session-properties</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/metabase-v0-57-3-public-google-oauth-config-exposed</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/metabase-v0-57-7-2-setup-token-api-docs-reset-oracle</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/mid-size-platform-targets</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/minio-bucket-enumeration-reveals-kyc-payments-users</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/minio-images-bucket-anonymous-write-supply-chain</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/minio-s3-bucket-public-listing-images-bucket-high</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/minio-s3-cors-wildcard-credentials-with-kyc-buckets-present</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/missing-hmac-signature-across-all-plugins</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/monad-rpc-debug-namespace-enabled-without-api-key</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/monnify-webhook-forgery-no-signature-validation</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/monnify-webhook-signature-bypass-enables-unauthenticated-deposit-injecti</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/mono-connect-live-keys-exposed-banking-data-access</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/moonbase-admin-panel-source-code-exposure-via-cf-access-bypass</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/move-pusher-authentication-to-server-side-only</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/multiple-payment-processors-hardcoded</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/multiple-secret-keys-exposed-in-production-js-bundle</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/n8n-workflow-automation-platform-exposed</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/n8n-workflow-automation-platform-publicly-accessible</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/new-admin-account-takeover-via-password-reset-chain-otp-brute-force</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/new-complete-admin-console-architecture-leak-via-javascript-source-maps</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/new-platforms-critical-findings</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/new-platforms-scan</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/nextauth-authentication-bypass-via-social-login-flow</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/ngrok-dev-url-leak-in-production-cors-wildcard</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/no-https-all-credentials-in-plaintext-over-http</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/no-rate-limiting-on-authentication-endpoints-enables-brute-force</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/no-rate-limiting-on-pin-verification-and-login</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/nosql-injection-on-login-admin-login-and-signup</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/nosql-injection-on-userdetails-leading-to-admin-account-compromise</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/nova-admin-source-maps-publicly-accessible-9-9mb-1574-files</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/oauth-endpoints-operating-over-http</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/oauth2-token-forge-grants-30-day-access-token-for-any-user</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/odata-metadata-internal-architecture-exposure-high</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/odoo-erp-public-signup-full-stack-trace-information-disclosure-critical</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/okta-dev-tenant-serving-production-authentication</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/open-merchant-registration-with-automatic-admin-privileges</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/opensearch-security-alerts-10-000-events-readable</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/openvpn-as-server-publicly-accessible</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/operation-admin-panel-publicly-reachable</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/orm-injection-deep-exploitation</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/otc-api-accepts-hardcoded-localhost-3003-as-cors-origin</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/otc-source-map-exposes-856-files-and-razorpay-key</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/otc-subdomain-cname-misconfiguration-bubble-io</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/otp-brute-force-account-takeover-no-rate-limit</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/otp-rate-limiting-set-to-zero</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/otp-token-injection-leads-to-mass-account-takeover</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/outdated-camera-firmware-with-multiple-known-cves-v3-4-87-modify</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/ownership-slot-mismatch-bricks-smart-wallet-after-claim-transition</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/partner-api-full-account-management-via-public-npm-package</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/partner-portal-source-map-exposure</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/passbolt-full-config-gpg-key-exfiltration-via-ssrf</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/password-hash-exposure-on-registration</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/password-reset-otp-brute-force-leads-to-full-account-takeover</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/password-reset-pin-verify-returns-200-for-any-pin</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/password-reset-token-brute-force-no-rate-limit</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/password-reset-token-leakage-rate-limit-bypass-enables-ato</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/password-reset-token-leaked-in-response-body-full-ato</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/patient-medical-data-endpoints-discoverable</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/payborda-dashboard-source-maps-expose-1492-files</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/paymapi-payment-api-documentation-fully-open</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/payment-api-endpoints-accessible-without-authentication-high</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/payment-callback-without-webhook-signature-verification</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/payment-gateway-credentials-hardcoded-in-production-js</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/payment-otp-brute-force-zain-simpaisa-zero-rate-limit</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/payment-provider-toggle-enables-remote-dos</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/payment-webhook-signature-scheme-fully-disclosed</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/payout-service-directory-listing-redbiller-webhook-data-exposure-critica</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/payplus-1dfdf-firestore-full-crud-plaintext-passwords-13-554-kyc</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/paystack-live-key-exposed-in-frontend</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/phase3-critical-findings</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/phone-verification-set-to-mock-mode-in-production</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/pim-admin-panel-wasm-dll-source-code-disclosure</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/pin-overwrite-without-old-pin-verification-critical-cvss-8-8</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/postgresql-database-information-disclosure</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/pre-auth-bypass-on-accounts-and-order-submit-apis</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/pre-auth-rce-via-fastjson-ref-chain</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/pre-auth-user-existence-oracle-via-v3-customers-id</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/predictable-apikey-via-exposed-encryptalgo-forge-any-user-token</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/predictive-audience-api-exposed-unauthenticated-idor-swagger-pipeline-ex</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/price-manipulation-via-negative-debt-parameter</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/private-channel-auth-bypass-via-otp-hmac</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/production-api-authentication-bypass-via-encryption-key-exposure</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/production-api-key-client-id-leaked-in-merchant-panel-js</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/production-kyb-compliance-api-internet-reachable</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/production-mysql-user-created-via-stacked-query</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/production-otp-bypass-via-test-account-backdoor</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/production-pg2-jwt-issuer-validation-bypass-for-fund-transfer</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/production-rce-chain-via-wazuh-agent-group-configuration-injection</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/production-runtime-config-exposed-via-config-endpoints</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/production-secret-token-hardcoded-in-client-side-javascript</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/production-source-maps-exposed</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/production-widget-uses-dev-login-backdoor-commented-access-key</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/prometheus-metrics-14-754-lines-exposure</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/public-gcs-buckets-6-of-17-anonymously-listable</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/public-postman-api-documentation-with-production-data-critical</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/push-notification-send-to-all-users-via-firebase</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/pusher-e2e-encryption-key-hardcoded-full-trade-surveillance</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/queue-manipulation-via-csrf-token-extraction-job-retry-batch-retry</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/rabbitmq-default-credentials-guest-guest</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/rabbitmq-management-console-exposed-to-internet</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/race-condition-in-financial-operations</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/race-condition-parallel-primer-tokens-no-mutex</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/rancher-dashboard-ui-publicly-accessible</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/rancher-kubernetes-management-api-publicly-accessible</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/rate-limiter-dos-via-cross-segment-outflow-reduction-ineffectiveness</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/rate-manipulation-via-patch-rate</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/rbac-structure-full-exposure-11-roles</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/real-time-kyc-data-leakage-via-kafka</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/realtime-xss-mass-scan</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/recaptcha-v3-secret-key-exposed-in-client-javascript</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/redacted-2012-55-cve-research</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/redacted-base-url-override-for-api-endpoint-hijacking</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/redacted-billing-findings-proven</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/redacted-billing-research</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/redacted-deep-dive-v2</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/redacted-final-exploit</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/redacted-full-report</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/redacted-my-default-creds-report</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/redacted-oauth-oidc-exploitation</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/redacted-rtsp-audit</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/redacted-security-assessment-report-2026</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/redacted-ssh-2012-55-multiple-critical-cves-14-years-old</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/redacted-ssrf-applepay</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/redacted-ssrf-azure-infrastructure</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/redacted-staging-deep-security-assessment</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/redacted-wr841n-pentest</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/redis-commander-unauth-full-read-write-access</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/redis-full-control-via-ssrf-crlf-injection</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/registration-pin-verification-bypass-via-activate-account</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/rekyc-encryption-equals-no-encryption-fixed-static-key</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/reverse-authentication-logic-on-notification-escrowpayout-critical</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/risevest-admin-panel-with-kyc-management-exposed</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/roqqu-aes-256-ctr-encryption-key-exposed-full-api-traffic-decryption</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/roqqu-kyc-system-source-map-exposure</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/roqqu-unsigned-cloudinary-upload-to-kyc-document-folder</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/round6-deep-exploitation</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/rsa-private-key-exposed-in-html-source</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/s3-bucket-coincola-user-exposed</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/s3-bucket-kyc-data-mass-exposure-1352-documents</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/s3-bucket-kyc-data-mass-exposure-with-versioning-recovery</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/s3-full-read-write-delete-via-unauthenticated-cognito-role</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/safehaven-payment-webhook-no-signature-verification</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/sandbox-horizon-dashboard-unauthenticated</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/sea-mena-turkey-scan</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/security-finding</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/segment-analytics-write-key-exposed-event-injection-verified</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/self-hosted-sentry-event-injection-exchange</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/self-hosted-sentry-event-injection-verified</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/sentry-dsn-event-injection-production-project</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/sentry-dsn-exposed-in-admin-panel-event-injection-verified</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/sentry-dsn-exposed-with-event-injection</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/sentry-dsn-exposure-event-injection-2-projects</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/sentry-dsn-exposure-event-injection-stored-xss-via-error-events</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/serversocket-port-binding-via-deserialization</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/session-key-architecture-disclosed-in-source</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/session-not-invalidated-after-password-change-on-payment-gateway</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/seven-internal-microservice-apis-exposed-on-public-internet</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/seven-unauthenticated-payment-webhook-endpoints-paypal-stripe-coinbase-s</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/shopify-payment-test-environment-api-key-exposure-critical</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/shopware6-plugin-webhook-no-token-validation</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/shopware6-webhook-csrf-protection-disabled</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/shyft-mainnet-rpc-api-key-hardcoded</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/signalr-chathub-unauthenticated-jwt-token-issuance</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/signed-ppm-investor-contracts-public-in-startups-bucket</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/signoz-enterprise-monitoring-platform-public-exposure-high</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/signup-response-leaks-2fa-secret-bcrypt-hash-and-otp</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/six-api-keys-secrets-hardcoded-in-production-javascript</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/smartapi-source-maps-exposed-6-2mb-full-frontend</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/soketi-self-hosted-pusher-key-exposed-real-time-message-interception</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/sonarqube-v10-6-0-exposed-with-cve-2024-47004</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/sonata-admin-panel-web-debug-toolbar-exposed</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/source-map-exposure-10-products-782-5-mb-748-maps</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/source-map-exposure-71mb-with-aws-keys-payment-keys</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/source-map-exposure-243-source-files-10-9mb-full-frontend</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/source-map-exposure-api-endpoints-and-bank-account-validation-logic-crit</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/source-map-exposure-full-application-source-code-high</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/source-map-exposure-on-3-staging-apps-944-source-files</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/splitpay-app-storage-open</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/spring-boot-actuator-actuator-health-exposes-infrastructure</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/spring-boot-actuator-redacted-ui-exposure-bydatawelive-redacted-ng-high</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/spring-boot-admin-panel-publicly-reachable</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/sql-injection-full-database-compromise-14-8m-records</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/sql-injection-on-limit-clause-of-trade-endpoint</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/sql-injection-on-page-param-stored-procedure-discovery</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/sql-injection-via-table-name-3x-cloudflare-waf-bypass</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/ssl-certificate-pinning-keys-internal-config-exposed-via-public-api</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/ssrf-full-data-exfiltration-via-303-redirect-chain</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/ssrf-ip-format-bypass-no-ssrf-filter</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/ssrf-to-internal-gke-services</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/staging-do-spaces-credentials-admin-panel-source-code-exposed</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/staging-environment-dev-exposed-to-internet</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/staging-exchange-app-api-docs-public</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/stomp-broker-authentication-bypass</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/stomp-message-injection-into-topics</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/stomp-odds-injection-10-manipulation</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/stored-xss-via-bank-account-fields-high-cvss-7-6</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/stored-xss-via-feedback-form-high-cvss-7-3</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/strapi-api-token-leaked-in-client-side-javascript</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/strapi-cms-open-registration-with-jwt-issuance</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/strapi-cms-unauthenticated-blog-content-modification</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/strapi-cors-wildcard-origin-reflection-with-credentials</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/subdomain-information-disclosure-low</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/subdomain-takeover-img-vendor-dangling-wp-engine-cname</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/subdomain-takeover-on-bello-marketing-subdomain-railway-dangling</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/sumsub-kyc-webhook-forgery-no-hmac-validation</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/sumsub-webhook-forgery-kyc-bypass</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/sumsub-webhook-without-signature-verification</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/superadmin-id-hardcoded-totp-uri-pattern-leaked</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/svix-webhook-dashboard-token-leak-via-webhooklogin-query</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/swagger-api-docs-laravel-ignition-active-in-production</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/swagger-api-postman-collection-fully-open</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/swagger-ui-exposed-on-3-domains</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/swagger-ui-full-api-specification-public-on-3-subdomains-critical</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/swagger-ui-publicly-accessible-on-api-subdomain</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/swap-limit-order-no-otp-funds-locked-without-verification</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/tanda-webhook-bullmq-redis-infrastructure-leak-via-content-type</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/telefon-numarasi-ekrani</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/telegram-document-upload-abuse</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/temporal-ui-unauthenticated-production-payment-data-exposure</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/tencent-cos-bucket-public-listing</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/the-tolgee-xliff-import-endpoint-does-not-disable-external-entity-proces</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/thirdparty-app-key-renewal-without-authentication-critical</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/tolgee-user-organization-data-exposure</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/totp-2fa-secret-exposed-in-plaintext-via-profile-api</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/totp-otp-verify-endpoint-brute-force-with-minimal-rate-limiting</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/translation-write-cdn-publish-supply-chain-attack</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/twa-javascript-bridge-launches-arbitrary-urls-inside-auth-context</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/twitter-x-brand-account-takeover-119k-followers</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/two-aws-s3-buckets-unauthenticated-object-access</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/two-freshdesk-subdomain-takeover-targets</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/uat-trading-platform-exposed-on-direct-ec2-with-live-routes</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/unauthenticated-admin-configuration-data-exposure</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/unauthenticated-admin-wallet-balance-per-customer-idor</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/unauthenticated-admin-wallet-transaction-history</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/unauthenticated-aion-banking-configuration-disclosure</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/unauthenticated-api-endpoints-expose-business-data-high</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/unauthenticated-api-keys-endpoint-exposes-288-business-keys</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/unauthenticated-cryptocurrency-withdrawal-endpoints</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/unauthenticated-database-dump-via-admin-crm-test-php</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/unauthenticated-database-dump-via-public-test-php</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/unauthenticated-debug-endpoint-leaks-internal-service-configuration</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/unauthenticated-discovery-config-exposes-287-keys-and-89-internal-hosts</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/unauthenticated-file-write-webhook-forgery-chain-critical</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/unauthenticated-gift-card-callback-forgery</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/unauthenticated-idor-dumps-1-73m-investor-pii-and-kyc-photos</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/unauthenticated-invoice-api-endpoints-request-void-cancel-mark-as-paid</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/unauthenticated-invoice-creation-via-idor</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/unauthenticated-kyc-data-access-mass-pii</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/unauthenticated-kyc-verification-forgery-via-smileid-callback</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/unauthenticated-laravel-log-viewer-exposes-db-backup-emails-and-admin-lo</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/unauthenticated-mass-customer-pii-exposure-via-graphql</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/unauthenticated-mass-otp-and-user-data-exposure</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/unauthenticated-mass-user-data-leak-via-chat-messages-endpoint</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/unauthenticated-ml-anomaly-detection-engine-redacted-ui-on-production</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/unauthenticated-otp-disclosure-via-trade-userdetails-enables-ato</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/unauthenticated-otp-flooding-via-graphql-getloyaltyotp</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/unauthenticated-otp-send-verify-chain-phone-takeover</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/unauthenticated-payment-event-injection-via-partner-callback</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/unauthenticated-payment-token-generation-endpoint</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/unauthenticated-platform-settings-dump-36-anomaly-thresholds</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/unauthenticated-private-trade-chat-access</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/unauthenticated-refund-claim-via-uuid</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/unauthenticated-sidekiq-dashboard</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/unauthenticated-socket-io-real-time-stream</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/unauthenticated-totp-otp-generation-enables-mass-user-enumeration</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/unauthenticated-transaction-csv-download-via-downloadtransactions</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/unauthenticated-user-deletion-endpoint</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/unauthenticated-user-profile-modification-via-smileid-callback</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/unauthenticated-username-enumeration-via-public-api</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/unauthenticated-webhook-callback-deposit-forgery</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/unauthenticated-xbox-order-creation-on-internal-api-redeem-cards-com</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/universal-cors-wildcard-on-392-api-endpoints</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/unlimited-live-payout-creation-without-verification-on-payment-gateway</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/unprotected-api-backend-without-waf-or-cdn</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/unregistered-staging-domain-takeover-traderjoexyz-dev</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/unrestricted-file-upload-with-php-short-tag-injection-high</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/unrestricted-firebase-authentication-registration</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/unrestricted-registration-otp-brute-force-chain</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/unrestricted-stomp-topic-wildcard-subscription</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/unsigned-validity-window-metadata-in-erc-4337-wallet-signature</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/updated-source-map-full-exploitation-achieved</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/uploadcare-mono-coinbase-pay-api-keys-exposed</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/user-app-full-source-code-exposure-via-source-map-502-files</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/user-enumeration-via-password-reset-endpoint</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/vendor-30k-kullaniciya-toplu-erisim-dogrulanmis-vektor-analizi</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/vendor-admin-api-spring-boot-actuator-deep-dive-origin-bypass-chain</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/vendor-api-authentication-authorization-findings</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/vendor-firebase-veritabani-tam-erisim-okuma-yazma</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/vendor-full-account-takeover-chain-end-to-end-proof</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/vendor-hashcash-consultants-infrastructure-vulnerability-assessment</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/vendor-kyc-document-access-testing-evidence</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/vendor-multi-tenant-isolation-assessment</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/vendor-p2p-partner-race-condition-financial-endpoint-security-test-repor</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/vendor-s3-bucket-full-compromise-deep-exfiltration-proof</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/vercel-deployment-credentials-internal-infra-leak</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/vip-wallet-access-control-bypass-non-vip-vip</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/vip-wallet-access-control-bypass</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/virtual-card-callback-without-webhook-signature-verification</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/vite-dev-server-in-production-source-disclosure</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/vite-dev-server-production-full-source-code-exposure</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/vite-dev-server-source-code-exposure-on-integrator-dashboard</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/vite-manifest-source-map-exposure-299-vue-components</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/vpn-redacted-com-admin-panel-source-map-hardcoded-secret-high</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/vpn-superuser-account-compromise-via-weak-credentials-critical</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/wazuh-siem-api-default-credentials-full-infrastructure-compromise</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/wazuh-siem-dashboard-public</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/webauthn-passkey-credential-id-mass-leakage</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/webhook-trigger-forgery-on-any-verification</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/whitelabel-partner-data-and-mongodb-objectids-exposed-critical</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/widget-bundle-source-map-exposure</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/wildcard-cors-on-exchange-api-with-credentials</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/wildcard-cors-policy-on-financial-api</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/wildcard-dns-btmops-xyz-exposes-complete-infrastructure-topology</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/wildcard-dns-cors-reflection-enhances-phishing-to-ato</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/withdrawotp-stored-plaintext-leaked-via-admin-viewdetail</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/woocommerce-plugin-callback-missing-signature-verification-ssl-off</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/wordpress-directory-listing-exposes-3-567-upload-files-high</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/wordpress-rest-api-cors-origin-reflection-credentials-true</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/wordpress-xmlrpc-brute-force-amplification</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/wso2-api-manager-publisher-console-devportal-public-access-high</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/wsorder-bitbns-com-cors-origin-reflection-on-trade-engine</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/zendesk-admin-api-token-active-full-user-data-access</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/zero-amount-preauthorization-combined-with-mark-as-paid</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/zero-click-ato-via-unthrottled-reset-otp-oracle</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/zero-click-exploit</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/zero-otp-rate-limiting-enables-5-minute-account-brute-force</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/zero-price-primer-production-payment-tokens</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/zero-rate-limiting-on-all-authentication-endpoints</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/disclosures/zoho-oauth-client-secret-exposed-with-full-api-scope</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/engagement</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>monthly</changefreq><priority>0.9</priority></url><url><loc>https://www.memcyber.com/faq</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>monthly</changefreq><priority>0.6</priority></url><url><loc>https://www.memcyber.com/industries</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/methodology</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>monthly</changefreq><priority>0.9</priority></url><url><loc>https://www.memcyber.com/press</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>monthly</changefreq><priority>0.6</priority></url><url><loc>https://www.memcyber.com/privacy</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>yearly</changefreq><priority>0.2</priority></url><url><loc>https://www.memcyber.com/research</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/research/idor-chaining-fintech</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/research/move-capability-model-pitfalls</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/research/webhook-forgery-signature-validation</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url><url><loc>https://www.memcyber.com/security</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>monthly</changefreq><priority>0.6</priority></url><url><loc>https://www.memcyber.com/services</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>monthly</changefreq><priority>0.9</priority></url><url><loc>https://www.memcyber.com/terms</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>yearly</changefreq><priority>0.2</priority></url><url><loc>https://www.memcyber.com/toolkit</loc><lastmod>2026-04-21T12:25:22.272Z</lastmod><changefreq>weekly</changefreq><priority>0.8</priority></url></urlset>