Publicly disclosed vulnerabilities discovered by or reported to Fluid Attacks
External pentesters
Askbot 0.12.2 - Insecure Direct Object Reference (IDOR)
5.3
Medium
CVE-2026-1213
Published date:
Jan 27, 2026
Discovered by
Daniel Esteban Celis
Our pentesters
Svelte 5.46.0 - Hydratable Key Script-Breakout XSS (SSR)
5.3
Medium
CVE-2025-15265
Published date:
Jan 15, 2026
Discovered by
Camilo Vera
Our pentesters
Nu Html Checker (validator.nu) - Restriction bypass vulnerability allowing local SSRF
6.9
Medium
CVE-2025-15104
Published date:
Jan 13, 2026
Discovered by
Oscar Uribe
Our pentesters
Quill 2.0.3 - Lack of data validation in HTML export allowing XSS
5.1
Medium
CVE-2025-15056
Published date:
Jan 13, 2026
Discovered by
Cristian Vargas
Our pentesters
Eddie VPN 2.24.6 - Local Privilege Escalation
8.5
High
CVE-2025-14979
Published date:
Jan 6, 2026
Discovered by
Oscar Uribe
Our pentesters
BuhoNTFS 1.3.2 - Local Privilege Escalation
8.5
High
CVE-2025-13733
Published date:
Dec 12, 2025
Discovered by
Oscar Uribe
Our pentesters
Code Injection in Wave Term v0.12.2 allowing TCC Bypass
6.9
Medium
CVE-2025-12843
Published date:
Dec 12, 2025
Discovered by
Oscar Uribe
External pentesters
i-Educar 2.10.0 - Stored Cross-Site Scripting (XSS) in admin panel
4.8
Medium
CVE-2025-9638
Published date:
Dec 9, 2025
Discovered by
Marcelo Queiroz
Load more
External pentesters
Askbot 0.12.2 - Insecure Direct Object Reference (IDOR)
5.3
Medium
CVE-2026-1213
Published date:
Jan 27, 2026
Discovered by
Daniel Esteban Celis
Our pentesters
Svelte 5.46.0 - Hydratable Key Script-Breakout XSS (SSR)
5.3
Medium
CVE-2025-15265
Published date:
Jan 15, 2026
Discovered by
Camilo Vera
Our pentesters
Nu Html Checker (validator.nu) - Restriction bypass vulnerability allowing local SSRF
6.9
Medium
CVE-2025-15104
Published date:
Jan 13, 2026
Discovered by
Oscar Uribe
Our pentesters
Quill 2.0.3 - Lack of data validation in HTML export allowing XSS
5.1
Medium
CVE-2025-15056
Published date:
Jan 13, 2026
Discovered by
Cristian Vargas
Our pentesters
Eddie VPN 2.24.6 - Local Privilege Escalation
8.5
High
CVE-2025-14979
Published date:
Jan 6, 2026
Discovered by
Oscar Uribe
Our pentesters
BuhoNTFS 1.3.2 - Local Privilege Escalation
8.5
High
CVE-2025-13733
Published date:
Dec 12, 2025
Discovered by
Oscar Uribe
Our pentesters
Code Injection in Wave Term v0.12.2 allowing TCC Bypass
6.9
Medium
CVE-2025-12843
Published date:
Dec 12, 2025
Discovered by
Oscar Uribe
External pentesters
i-Educar 2.10.0 - Stored Cross-Site Scripting (XSS) in admin panel
4.8
Medium
CVE-2025-9638
Published date:
Dec 9, 2025
Discovered by
Marcelo Queiroz
Load more
External pentesters
Askbot 0.12.2 - Insecure Direct Object Reference (IDOR)
5.3
Medium
CVE-2026-1213
Published date:
Jan 27, 2026
Discovered by
Daniel Esteban Celis
Our pentesters
Svelte 5.46.0 - Hydratable Key Script-Breakout XSS (SSR)
5.3
Medium
CVE-2025-15265
Published date:
Jan 15, 2026
Discovered by
Camilo Vera
Our pentesters
Nu Html Checker (validator.nu) - Restriction bypass vulnerability allowing local SSRF
6.9
Medium
CVE-2025-15104
Published date:
Jan 13, 2026
Discovered by
Oscar Uribe
Our pentesters
Quill 2.0.3 - Lack of data validation in HTML export allowing XSS
5.1
Medium
CVE-2025-15056
Published date:
Jan 13, 2026
Discovered by
Cristian Vargas
Our pentesters
Eddie VPN 2.24.6 - Local Privilege Escalation
8.5
High
CVE-2025-14979
Published date:
Jan 6, 2026
Discovered by
Oscar Uribe
Our pentesters
BuhoNTFS 1.3.2 - Local Privilege Escalation
8.5
High
CVE-2025-13733
Published date:
Dec 12, 2025
Discovered by
Oscar Uribe
Our pentesters
Code Injection in Wave Term v0.12.2 allowing TCC Bypass
6.9
Medium
CVE-2025-12843
Published date:
Dec 12, 2025
Discovered by
Oscar Uribe
External pentesters
i-Educar 2.10.0 - Stored Cross-Site Scripting (XSS) in admin panel
4.8
Medium
CVE-2025-9638
Published date:
Dec 9, 2025
Discovered by
Marcelo Queiroz
Load more
External pentesters
Askbot 0.12.2 - Insecure Direct Object Reference (IDOR)
5.3
Medium
CVE-2026-1213
Published date:
Jan 27, 2026
Discovered by
Daniel Esteban Celis
Our pentesters
Svelte 5.46.0 - Hydratable Key Script-Breakout XSS (SSR)
5.3
Medium
CVE-2025-15265
Published date:
Jan 15, 2026
Discovered by
Camilo Vera
Our pentesters
Nu Html Checker (validator.nu) - Restriction bypass vulnerability allowing local SSRF
6.9
Medium
CVE-2025-15104
Published date:
Jan 13, 2026
Discovered by
Oscar Uribe
Our pentesters
Quill 2.0.3 - Lack of data validation in HTML export allowing XSS
5.1
Medium
CVE-2025-15056
Published date:
Jan 13, 2026
Discovered by
Cristian Vargas
Our pentesters
Eddie VPN 2.24.6 - Local Privilege Escalation
8.5
High
CVE-2025-14979
Published date:
Jan 6, 2026
Discovered by
Oscar Uribe
Our pentesters
BuhoNTFS 1.3.2 - Local Privilege Escalation
8.5
High
CVE-2025-13733
Published date:
Dec 12, 2025
Discovered by
Oscar Uribe
Our pentesters
Code Injection in Wave Term v0.12.2 allowing TCC Bypass
6.9
Medium
CVE-2025-12843
Published date:
Dec 12, 2025
Discovered by
Oscar Uribe
External pentesters
i-Educar 2.10.0 - Stored Cross-Site Scripting (XSS) in admin panel
4.8
Medium
CVE-2025-9638
Published date:
Dec 9, 2025
Discovered by
Marcelo Queiroz
Load more


Learn about our policy for disclosing advisories of vulnerabilities in third-party, open-source products.


Start your 21-day free trial
Discover the benefits of our Continuous Hacking solution, which organizations of all sizes are already enjoying.


Start your 21-day free trial
Discover the benefits of our Continuous Hacking solution, which organizations of all sizes are already enjoying.


Start your 21-day free trial
Discover the benefits of our Continuous Hacking solution, which organizations of all sizes are already enjoying.


Fluid Attacks' solutions enable organizations to identify, prioritize, and remediate vulnerabilities in their software throughout the SDLC. Supported by AI, automated tools, and pentesters, Fluid Attacks accelerates companies' risk exposure mitigation and strengthens their cybersecurity posture.
Targets
Subscribe to our newsletter
Stay updated on our upcoming events and latest blog posts, advisories and other engaging resources.
© 2026 Fluid Attacks. We hack your software.

Fluid Attacks' solutions enable organizations to identify, prioritize, and remediate vulnerabilities in their software throughout the SDLC. Supported by AI, automated tools, and pentesters, Fluid Attacks accelerates companies' risk exposure mitigation and strengthens their cybersecurity posture.
Targets
Subscribe to our newsletter
Stay updated on our upcoming events and latest blog posts, advisories and other engaging resources.
© 2026 Fluid Attacks. We hack your software.

Fluid Attacks' solutions enable organizations to identify, prioritize, and remediate vulnerabilities in their software throughout the SDLC. Supported by AI, automated tools, and pentesters, Fluid Attacks accelerates companies' risk exposure mitigation and strengthens their cybersecurity posture.
Targets
Subscribe to our newsletter
Stay updated on our upcoming events and latest blog posts, advisories and other engaging resources.
© 2026 Fluid Attacks. We hack your software.





