Publicly disclosed vulnerabilities discovered by or reported to Fluid Attacks

Buscar por término

Search filters

Discovered by

All

Severity

All

Our pentesters

Svelte 5.46.0 - Hydratable Key Script-Breakout XSS (SSR)

5.3

Medium

CVE-2025-15265

Published date:

15 ene 2026

Discovered by

Camilo Vera

Our pentesters

Nu Html Checker (validator.nu) - Restriction bypass vulnerability allowing local SSRF

6.9

Medium

CVE-2025-15104

Published date:

13 ene 2026

Discovered by

Oscar Uribe

Our pentesters

Quill 2.0.3 - Lack of data validation in HTML export allowing XSS

5.1

Medium

CVE-2025-15056

Published date:

13 ene 2026

Discovered by

Cristian Vargas

Our pentesters

Eddie VPN 2.24.6 - Local Privilege Escalation

8.5

High

CVE-2025-14979

Published date:

6 ene 2026

Discovered by

Oscar Uribe

Our pentesters

BuhoNTFS 1.3.2 - Local Privilege Escalation

8.5

High

CVE-2025-13733

Published date:

12 dic 2025

Discovered by

Oscar Uribe

Our pentesters

Code Injection in Wave Term v0.12.2 allowing TCC Bypass

6.9

Medium

CVE-2025-12843

Published date:

12 dic 2025

Discovered by

Oscar Uribe

External pentesters

i-Educar 2.10.0 - Stored Cross-Site Scripting (XSS) in admin panel

4.8

Medium

CVE-2025-9638

Published date:

9 dic 2025

Discovered by

Marcelo Queiroz

Our pentesters

Frappe Helpdesk 1.14.0 — SQL Injection in dashboard get_dashboard_data

8.6

High

CVE-2025-10655

Published date:

9 dic 2025

Discovered by

Cristian Vargas

Cargar más

Buscar por término

Search filters

Discovered by

All

Severity

All

Our pentesters

Svelte 5.46.0 - Hydratable Key Script-Breakout XSS (SSR)

5.3

Medium

CVE-2025-15265

Published date:

15 ene 2026

Discovered by

Camilo Vera

Our pentesters

Nu Html Checker (validator.nu) - Restriction bypass vulnerability allowing local SSRF

6.9

Medium

CVE-2025-15104

Published date:

13 ene 2026

Discovered by

Oscar Uribe

Our pentesters

Quill 2.0.3 - Lack of data validation in HTML export allowing XSS

5.1

Medium

CVE-2025-15056

Published date:

13 ene 2026

Discovered by

Cristian Vargas

Our pentesters

Eddie VPN 2.24.6 - Local Privilege Escalation

8.5

High

CVE-2025-14979

Published date:

6 ene 2026

Discovered by

Oscar Uribe

Our pentesters

BuhoNTFS 1.3.2 - Local Privilege Escalation

8.5

High

CVE-2025-13733

Published date:

12 dic 2025

Discovered by

Oscar Uribe

Our pentesters

Code Injection in Wave Term v0.12.2 allowing TCC Bypass

6.9

Medium

CVE-2025-12843

Published date:

12 dic 2025

Discovered by

Oscar Uribe

External pentesters

i-Educar 2.10.0 - Stored Cross-Site Scripting (XSS) in admin panel

4.8

Medium

CVE-2025-9638

Published date:

9 dic 2025

Discovered by

Marcelo Queiroz

Our pentesters

Frappe Helpdesk 1.14.0 — SQL Injection in dashboard get_dashboard_data

8.6

High

CVE-2025-10655

Published date:

9 dic 2025

Discovered by

Cristian Vargas

Cargar más

Buscar por término

Search filters

Discovered by

All

Severity

All

Our pentesters

Svelte 5.46.0 - Hydratable Key Script-Breakout XSS (SSR)

5.3

Medium

CVE-2025-15265

Published date:

15 ene 2026

Discovered by

Camilo Vera

Our pentesters

Nu Html Checker (validator.nu) - Restriction bypass vulnerability allowing local SSRF

6.9

Medium

CVE-2025-15104

Published date:

13 ene 2026

Discovered by

Oscar Uribe

Our pentesters

Quill 2.0.3 - Lack of data validation in HTML export allowing XSS

5.1

Medium

CVE-2025-15056

Published date:

13 ene 2026

Discovered by

Cristian Vargas

Our pentesters

Eddie VPN 2.24.6 - Local Privilege Escalation

8.5

High

CVE-2025-14979

Published date:

6 ene 2026

Discovered by

Oscar Uribe

Our pentesters

BuhoNTFS 1.3.2 - Local Privilege Escalation

8.5

High

CVE-2025-13733

Published date:

12 dic 2025

Discovered by

Oscar Uribe

Our pentesters

Code Injection in Wave Term v0.12.2 allowing TCC Bypass

6.9

Medium

CVE-2025-12843

Published date:

12 dic 2025

Discovered by

Oscar Uribe

External pentesters

i-Educar 2.10.0 - Stored Cross-Site Scripting (XSS) in admin panel

4.8

Medium

CVE-2025-9638

Published date:

9 dic 2025

Discovered by

Marcelo Queiroz

Our pentesters

Frappe Helpdesk 1.14.0 — SQL Injection in dashboard get_dashboard_data

8.6

High

CVE-2025-10655

Published date:

9 dic 2025

Discovered by

Cristian Vargas

Cargar más

Buscar por término

Search filters

Discovered by

All

Severity

All

Our pentesters

Svelte 5.46.0 - Hydratable Key Script-Breakout XSS (SSR)

5.3

Medium

CVE-2025-15265

Published date:

15 ene 2026

Discovered by

Camilo Vera

Our pentesters

Nu Html Checker (validator.nu) - Restriction bypass vulnerability allowing local SSRF

6.9

Medium

CVE-2025-15104

Published date:

13 ene 2026

Discovered by

Oscar Uribe

Our pentesters

Quill 2.0.3 - Lack of data validation in HTML export allowing XSS

5.1

Medium

CVE-2025-15056

Published date:

13 ene 2026

Discovered by

Cristian Vargas

Our pentesters

Eddie VPN 2.24.6 - Local Privilege Escalation

8.5

High

CVE-2025-14979

Published date:

6 ene 2026

Discovered by

Oscar Uribe

Our pentesters

BuhoNTFS 1.3.2 - Local Privilege Escalation

8.5

High

CVE-2025-13733

Published date:

12 dic 2025

Discovered by

Oscar Uribe

Our pentesters

Code Injection in Wave Term v0.12.2 allowing TCC Bypass

6.9

Medium

CVE-2025-12843

Published date:

12 dic 2025

Discovered by

Oscar Uribe

External pentesters

i-Educar 2.10.0 - Stored Cross-Site Scripting (XSS) in admin panel

4.8

Medium

CVE-2025-9638

Published date:

9 dic 2025

Discovered by

Marcelo Queiroz

Our pentesters

Frappe Helpdesk 1.14.0 — SQL Injection in dashboard get_dashboard_data

8.6

High

CVE-2025-10655

Published date:

9 dic 2025

Discovered by

Cristian Vargas

Cargar más

Learn about our policy for disclosing advisories of vulnerabilities in third-party, open-source products.

Inicia tu prueba gratuita de 21 días

Descubre los beneficios de nuestra solución Hacking Continuo, de la que ya disfrutan empresas de todos los tamaños.

Inicia tu prueba gratuita de 21 días

Descubre los beneficios de nuestra solución Hacking Continuo, de la que ya disfrutan empresas de todos los tamaños.

Inicia tu prueba gratuita de 21 días

Descubre los beneficios de nuestra solución Hacking Continuo, de la que ya disfrutan empresas de todos los tamaños.

Las soluciones de Fluid Attacks permiten a las organizaciones identificar, priorizar y remediar vulnerabilidades en su software a lo largo del SDLC. Con el apoyo de la IA, herramientas automatizadas y pentesters, Fluid Attacks acelera la mitigación de la exposición al riesgo de las empresas y fortalece su postura de ciberseguridad.

Lee un resumen de Fluid Attacks

Suscríbete a nuestro boletín

Mantente al día sobre nuestros próximos eventos y los últimos blog posts, advisories y otros recursos interesantes.

SOC 2 Type II

SOC 3

Las soluciones de Fluid Attacks permiten a las organizaciones identificar, priorizar y remediar vulnerabilidades en su software a lo largo del SDLC. Con el apoyo de la IA, herramientas automatizadas y pentesters, Fluid Attacks acelera la mitigación de la exposición al riesgo de las empresas y fortalece su postura de ciberseguridad.

Suscríbete a nuestro boletín

Mantente al día sobre nuestros próximos eventos y los últimos blog posts, advisories y otros recursos interesantes.

Mantente al día sobre nuestros próximos eventos y los últimos blog posts, advisories y otros recursos interesantes.

SOC 2 Type II

SOC 3

Las soluciones de Fluid Attacks permiten a las organizaciones identificar, priorizar y remediar vulnerabilidades en su software a lo largo del SDLC. Con el apoyo de la IA, herramientas automatizadas y pentesters, Fluid Attacks acelera la mitigación de la exposición al riesgo de las empresas y fortalece su postura de ciberseguridad.

Suscríbete a nuestro boletín

Mantente al día sobre nuestros próximos eventos y los últimos blog posts, advisories y otros recursos interesantes.

Mantente al día sobre nuestros próximos eventos y los últimos blog posts, advisories y otros recursos interesantes.

SOC 2 Type II

SOC 3