Publicly disclosed vulnerabilities discovered by or reported to Fluid Attacks

Search by term

Search filters

Discovered by

All

Severity

All

AI SAST Scanner

Corteza 2024.9.8 - SQL Injection in MSSQL JSON-path meta filter via incorrect T-SQL string escaping

6

Medium

CVE-2026-6093

Published date:

Sep 25, 2026

Detected by

Fluid Attacks AI SAST Scanner,

disclosed by

Oscar Uribe

Our pentesters

Root Browser Classic 3.3.0 - OS command injection through crafted SQLite filenames

8.5

High

CVE-2026-85082

Published date:

Sep 24, 2026

Discovered by

Andrés Ramos

Our pentesters

Secure Folder 1.2 - Plaintext vault files in shared storage bypass the PIN gate

6.8

Medium

CVE-2026-84283

Published date:

Sep 24, 2026

Discovered by

Andrés Ramos

Our pentesters

LimeSurvey Community Edition 7.0.14 - Reflected XSS in participant CSV import result via invalid attribute column name

7.4

High

CVE-2026-92730

Published date:

Sep 23, 2026

Discovered by

Miguel Gómez

Our pentesters

LimeSurvey Community Edition 7.0.14 - Reflected XSS through unescaped LSS survey-import warnings

7.4

High

CVE-2026-91775

Published date:

Sep 23, 2026

Discovered by

Miguel Gómez

External pentesters

NASA CryptoLib 1.5.0 - TC receive path accepts Security Associations from the wrong GVCID

8.7

High

CVE-2026-79954

Published date:

Sep 17, 2026

Discovered by

Romel Marín

Our pentesters

Gallery - Private Photo Vault 1.0.41 - Unauthenticated local-network HTTP file exposure

7.1

High

CVE-2026-77884

Published date:

Sep 14, 2026

Discovered by

Andrés Ramos

Our pentesters

Ekia File Manager 1.2.7 - Exported ContentProvider allows unauthorized file access

8.5

High

CVE-2026-81301

Published date:

Sep 14, 2026

Discovered by

Andrés Ramos

Load more

Search by term

Search filters

Discovered by

All

Severity

All

AI SAST Scanner

Corteza 2024.9.8 - SQL Injection in MSSQL JSON-path meta filter via incorrect T-SQL string escaping

6

Medium

CVE-2026-6093

Published date:

Sep 25, 2026

Detected by

Fluid Attacks AI SAST Scanner,

disclosed by

Oscar Uribe

Our pentesters

Root Browser Classic 3.3.0 - OS command injection through crafted SQLite filenames

8.5

High

CVE-2026-85082

Published date:

Sep 24, 2026

Discovered by

Andrés Ramos

Our pentesters

Secure Folder 1.2 - Plaintext vault files in shared storage bypass the PIN gate

6.8

Medium

CVE-2026-84283

Published date:

Sep 24, 2026

Discovered by

Andrés Ramos

Our pentesters

LimeSurvey Community Edition 7.0.14 - Reflected XSS in participant CSV import result via invalid attribute column name

7.4

High

CVE-2026-92730

Published date:

Sep 23, 2026

Discovered by

Miguel Gómez

Our pentesters

LimeSurvey Community Edition 7.0.14 - Reflected XSS through unescaped LSS survey-import warnings

7.4

High

CVE-2026-91775

Published date:

Sep 23, 2026

Discovered by

Miguel Gómez

External pentesters

NASA CryptoLib 1.5.0 - TC receive path accepts Security Associations from the wrong GVCID

8.7

High

CVE-2026-79954

Published date:

Sep 17, 2026

Discovered by

Romel Marín

Our pentesters

Gallery - Private Photo Vault 1.0.41 - Unauthenticated local-network HTTP file exposure

7.1

High

CVE-2026-77884

Published date:

Sep 14, 2026

Discovered by

Andrés Ramos

Our pentesters

Ekia File Manager 1.2.7 - Exported ContentProvider allows unauthorized file access

8.5

High

CVE-2026-81301

Published date:

Sep 14, 2026

Discovered by

Andrés Ramos

Load more

Search by term

Search filters

Discovered by

All

Severity

All

AI SAST Scanner

Corteza 2024.9.8 - SQL Injection in MSSQL JSON-path meta filter via incorrect T-SQL string escaping

6

Medium

CVE-2026-6093

Published date:

Sep 25, 2026

Discovered by

Oscar Uribe

Detected by

Fluid Attacks AI SAST Scanner,

disclosed by

Oscar Uribe

Our pentesters

Root Browser Classic 3.3.0 - OS command injection through crafted SQLite filenames

8.5

High

CVE-2026-85082

Published date:

Sep 24, 2026

Discovered by

Andrés Ramos

Our pentesters

Secure Folder 1.2 - Plaintext vault files in shared storage bypass the PIN gate

6.8

Medium

CVE-2026-84283

Published date:

Sep 24, 2026

Discovered by

Andrés Ramos

Our pentesters

LimeSurvey Community Edition 7.0.14 - Reflected XSS in participant CSV import result via invalid attribute column name

7.4

High

CVE-2026-92730

Published date:

Sep 23, 2026

Discovered by

Miguel Gómez

Our pentesters

LimeSurvey Community Edition 7.0.14 - Reflected XSS through unescaped LSS survey-import warnings

7.4

High

CVE-2026-91775

Published date:

Sep 23, 2026

Discovered by

Miguel Gómez

External pentesters

NASA CryptoLib 1.5.0 - TC receive path accepts Security Associations from the wrong GVCID

8.7

High

CVE-2026-79954

Published date:

Sep 17, 2026

Discovered by

Romel Marín

Our pentesters

Gallery - Private Photo Vault 1.0.41 - Unauthenticated local-network HTTP file exposure

7.1

High

CVE-2026-77884

Published date:

Sep 14, 2026

Discovered by

Andrés Ramos

Our pentesters

Ekia File Manager 1.2.7 - Exported ContentProvider allows unauthorized file access

8.5

High

CVE-2026-81301

Published date:

Sep 14, 2026

Discovered by

Andrés Ramos

Load more

Learn about our policy for disclosing advisories of vulnerabilities in third-party, open-source products.

Reduce risk without slowing delivery

Reduce risk without slowing delivery

All in one continuous security program powered by AI, scanners, and pentesters.

All in one continuous security program powered by AI, scanners, and pentesters.

Prevent

Prevent

Prevent

Detect

Detect

Detect

Manage

Manage

Manage

Remediate

Remediate

Remediate