Publicly disclosed vulnerabilities discovered by or reported to Fluid Attacks

Search by term

Search filters

Discovered by

All

Severity

All

Our pentesters

NestJS 11.1.13 - Lack of data validation allowing authentication/authorization bypass

8.2

High

CVE-2026-2293

Published date:

Feb 27, 2026

Discovered by

Cristian Vargas

Our pentesters

Fastify middie 9.1.0 - Improper path normalization

8.2

High

CVE-2026-2880

Published date:

Feb 27, 2026

Discovered by

Cristian Vargas

Our pentesters

BuhoCleaner 1.15.2 - Local Privilege Escalation via PID reuse attack

7.3

High

CVE-2026-0924

Published date:

Feb 2, 2026

Discovered by

Oscar Uribe

External pentesters

Askbot 0.12.2 - Insecure Direct Object Reference (IDOR)

5.3

Medium

CVE-2026-1213

Published date:

Jan 27, 2026

Discovered by

Daniel Esteban Celis

Our pentesters

Svelte 5.46.0 - Hydratable Key Script-Breakout XSS (SSR)

5.3

Medium

CVE-2025-15265

Published date:

Jan 15, 2026

Discovered by

Camilo Vera

Our pentesters

Nu Html Checker (validator.nu) - Restriction bypass vulnerability allowing local SSRF

6.9

Medium

CVE-2025-15104

Published date:

Jan 13, 2026

Discovered by

Oscar Uribe

Our pentesters

Quill 2.0.3 - Lack of data validation in HTML export allowing XSS

5.1

Medium

CVE-2025-15056

Published date:

Jan 13, 2026

Discovered by

Cristian Vargas

Our pentesters

Eddie VPN 2.24.6 - Local Privilege Escalation

8.5

High

CVE-2025-14979

Published date:

Jan 6, 2026

Discovered by

Oscar Uribe

Load more

Search by term

Search filters

Discovered by

All

Severity

All

Our pentesters

NestJS 11.1.13 - Lack of data validation allowing authentication/authorization bypass

8.2

High

CVE-2026-2293

Published date:

Feb 27, 2026

Discovered by

Cristian Vargas

Our pentesters

Fastify middie 9.1.0 - Improper path normalization

8.2

High

CVE-2026-2880

Published date:

Feb 27, 2026

Discovered by

Cristian Vargas

Our pentesters

BuhoCleaner 1.15.2 - Local Privilege Escalation via PID reuse attack

7.3

High

CVE-2026-0924

Published date:

Feb 2, 2026

Discovered by

Oscar Uribe

External pentesters

Askbot 0.12.2 - Insecure Direct Object Reference (IDOR)

5.3

Medium

CVE-2026-1213

Published date:

Jan 27, 2026

Discovered by

Daniel Esteban Celis

Our pentesters

Svelte 5.46.0 - Hydratable Key Script-Breakout XSS (SSR)

5.3

Medium

CVE-2025-15265

Published date:

Jan 15, 2026

Discovered by

Camilo Vera

Our pentesters

Nu Html Checker (validator.nu) - Restriction bypass vulnerability allowing local SSRF

6.9

Medium

CVE-2025-15104

Published date:

Jan 13, 2026

Discovered by

Oscar Uribe

Our pentesters

Quill 2.0.3 - Lack of data validation in HTML export allowing XSS

5.1

Medium

CVE-2025-15056

Published date:

Jan 13, 2026

Discovered by

Cristian Vargas

Our pentesters

Eddie VPN 2.24.6 - Local Privilege Escalation

8.5

High

CVE-2025-14979

Published date:

Jan 6, 2026

Discovered by

Oscar Uribe

Load more

Search by term

Search filters

Discovered by

All

Severity

All

Our pentesters

NestJS 11.1.13 - Lack of data validation allowing authentication/authorization bypass

8.2

High

CVE-2026-2293

Published date:

Feb 27, 2026

Discovered by

Cristian Vargas

Our pentesters

Fastify middie 9.1.0 - Improper path normalization

8.2

High

CVE-2026-2880

Published date:

Feb 27, 2026

Discovered by

Cristian Vargas

Our pentesters

BuhoCleaner 1.15.2 - Local Privilege Escalation via PID reuse attack

7.3

High

CVE-2026-0924

Published date:

Feb 2, 2026

Discovered by

Oscar Uribe

External pentesters

Askbot 0.12.2 - Insecure Direct Object Reference (IDOR)

5.3

Medium

CVE-2026-1213

Published date:

Jan 27, 2026

Discovered by

Daniel Esteban Celis

Our pentesters

Svelte 5.46.0 - Hydratable Key Script-Breakout XSS (SSR)

5.3

Medium

CVE-2025-15265

Published date:

Jan 15, 2026

Discovered by

Camilo Vera

Our pentesters

Nu Html Checker (validator.nu) - Restriction bypass vulnerability allowing local SSRF

6.9

Medium

CVE-2025-15104

Published date:

Jan 13, 2026

Discovered by

Oscar Uribe

Our pentesters

Quill 2.0.3 - Lack of data validation in HTML export allowing XSS

5.1

Medium

CVE-2025-15056

Published date:

Jan 13, 2026

Discovered by

Cristian Vargas

Our pentesters

Eddie VPN 2.24.6 - Local Privilege Escalation

8.5

High

CVE-2025-14979

Published date:

Jan 6, 2026

Discovered by

Oscar Uribe

Load more

Learn about our policy for disclosing advisories of vulnerabilities in third-party, open-source products.

Start your 21-day free trial

Discover the benefits of our Continuous Hacking solution, which organizations of all sizes are already enjoying.

Start your 21-day free trial

Discover the benefits of our Continuous Hacking solution, which organizations of all sizes are already enjoying.

Start your 21-day free trial

Discover the benefits of our Continuous Hacking solution, which organizations of all sizes are already enjoying.

Fluid Attacks' solutions enable organizations to identify, prioritize, and remediate vulnerabilities in their software throughout the SDLC. Supported by AI, automated tools, and pentesters, Fluid Attacks accelerates companies' risk exposure mitigation and strengthens their cybersecurity posture.

Get an AI summary of Fluid Attacks

Subscribe to our newsletter

Stay updated on our upcoming events and latest blog posts, advisories and other engaging resources.

© 2026 Fluid Attacks. We hack your software.

Fluid Attacks' solutions enable organizations to identify, prioritize, and remediate vulnerabilities in their software throughout the SDLC. Supported by AI, automated tools, and pentesters, Fluid Attacks accelerates companies' risk exposure mitigation and strengthens their cybersecurity posture.

Subscribe to our newsletter

Stay updated on our upcoming events and latest blog posts, advisories and other engaging resources.

Get an AI summary of Fluid Attacks

© 2026 Fluid Attacks. We hack your software.

Fluid Attacks' solutions enable organizations to identify, prioritize, and remediate vulnerabilities in their software throughout the SDLC. Supported by AI, automated tools, and pentesters, Fluid Attacks accelerates companies' risk exposure mitigation and strengthens their cybersecurity posture.

Subscribe to our newsletter

Stay updated on our upcoming events and latest blog posts, advisories and other engaging resources.

Get an AI summary of Fluid Attacks

© 2026 Fluid Attacks. We hack your software.

Meet us at RSA Conference™ 2026 at booth N-4614! Book a demo on-site.

Meet us at RSA Conference™ 2026 at booth N-4614! Book a demo on-site.

Meet us at RSA Conference™ 2026 at booth N-4614! Book a demo on-site.