Publicly disclosed vulnerabilities discovered by or reported to Fluid Attacks

Buscar por término

Search filters

Discovered by

All

Severity

All

Our pentesters

BuhoNTFS 1.3.2 - Local Privilege Escalation

8.5

High

CVE-2025-13733

Published date:

12 dic 2025

Discovered by

Oscar Uribe

Our pentesters

Code Injection in Wave Term v0.12.2 allowing TCC Bypass

6.9

Medium

CVE-2025-12843

Published date:

12 dic 2025

Discovered by

Oscar Uribe

External pentesters

i-Educar 2.10.0 - Stored Cross-Site Scripting (XSS) in admin panel

4.8

Medium

CVE-2025-9638

Published date:

9 dic 2025

Discovered by

Marcelo Queiroz

Our pentesters

Frappe Helpdesk 1.14.0 — SQL Injection in dashboard get_dashboard_data

8.6

High

CVE-2025-10655

Published date:

9 dic 2025

Discovered by

Cristian Vargas

Our pentesters

Frappe CRM 1.53.1 — Multiple SQL Injections in Dashboard Controller

7.1

High

CVE-2025-11461

Published date:

26 nov 2025

Discovered by

Cristian Vargas

Our pentesters

OpenSearch 3.2.0 - Nested Boolean/Disjunction Asymmetric DoS

8.3

High

CVE-2025-9624

Published date:

25 nov 2025

Discovered by

Camilo Vera

Our pentesters

iStat Menus 7.10.4 - Local Privilege Escalation

8.5

High

CVE-2025-11921

Published date:

7 nov 2025

Discovered by

Oscar Uribe

Our pentesters

OpenSupports 4.11.0 — SSRF via test imap and smtp endpoints

6.9

Medium

CVE-2025-10695

Published date:

3 oct 2025

Discovered by

Cristian Vargas

Cargar más

Buscar por término

Search filters

Discovered by

All

Severity

All

Our pentesters

BuhoNTFS 1.3.2 - Local Privilege Escalation

8.5

High

CVE-2025-13733

Published date:

12 dic 2025

Discovered by

Oscar Uribe

Our pentesters

Code Injection in Wave Term v0.12.2 allowing TCC Bypass

6.9

Medium

CVE-2025-12843

Published date:

12 dic 2025

Discovered by

Oscar Uribe

External pentesters

i-Educar 2.10.0 - Stored Cross-Site Scripting (XSS) in admin panel

4.8

Medium

CVE-2025-9638

Published date:

9 dic 2025

Discovered by

Marcelo Queiroz

Our pentesters

Frappe Helpdesk 1.14.0 — SQL Injection in dashboard get_dashboard_data

8.6

High

CVE-2025-10655

Published date:

9 dic 2025

Discovered by

Cristian Vargas

Our pentesters

Frappe CRM 1.53.1 — Multiple SQL Injections in Dashboard Controller

7.1

High

CVE-2025-11461

Published date:

26 nov 2025

Discovered by

Cristian Vargas

Our pentesters

OpenSearch 3.2.0 - Nested Boolean/Disjunction Asymmetric DoS

8.3

High

CVE-2025-9624

Published date:

25 nov 2025

Discovered by

Camilo Vera

Our pentesters

iStat Menus 7.10.4 - Local Privilege Escalation

8.5

High

CVE-2025-11921

Published date:

7 nov 2025

Discovered by

Oscar Uribe

Our pentesters

OpenSupports 4.11.0 — SSRF via test imap and smtp endpoints

6.9

Medium

CVE-2025-10695

Published date:

3 oct 2025

Discovered by

Cristian Vargas

Cargar más

Buscar por término

Search filters

Discovered by

All

Severity

All

Our pentesters

BuhoNTFS 1.3.2 - Local Privilege Escalation

8.5

High

CVE-2025-13733

Published date:

12 dic 2025

Discovered by

Oscar Uribe

Our pentesters

Code Injection in Wave Term v0.12.2 allowing TCC Bypass

6.9

Medium

CVE-2025-12843

Published date:

12 dic 2025

Discovered by

Oscar Uribe

External pentesters

i-Educar 2.10.0 - Stored Cross-Site Scripting (XSS) in admin panel

4.8

Medium

CVE-2025-9638

Published date:

9 dic 2025

Discovered by

Marcelo Queiroz

Our pentesters

Frappe Helpdesk 1.14.0 — SQL Injection in dashboard get_dashboard_data

8.6

High

CVE-2025-10655

Published date:

9 dic 2025

Discovered by

Cristian Vargas

Our pentesters

Frappe CRM 1.53.1 — Multiple SQL Injections in Dashboard Controller

7.1

High

CVE-2025-11461

Published date:

26 nov 2025

Discovered by

Cristian Vargas

Our pentesters

OpenSearch 3.2.0 - Nested Boolean/Disjunction Asymmetric DoS

8.3

High

CVE-2025-9624

Published date:

25 nov 2025

Discovered by

Camilo Vera

Our pentesters

iStat Menus 7.10.4 - Local Privilege Escalation

8.5

High

CVE-2025-11921

Published date:

7 nov 2025

Discovered by

Oscar Uribe

Our pentesters

OpenSupports 4.11.0 — SSRF via test imap and smtp endpoints

6.9

Medium

CVE-2025-10695

Published date:

3 oct 2025

Discovered by

Cristian Vargas

Cargar más

Buscar por término

Search filters

Discovered by

All

Severity

All

Our pentesters

BuhoNTFS 1.3.2 - Local Privilege Escalation

8.5

High

CVE-2025-13733

Published date:

12 dic 2025

Discovered by

Oscar Uribe

Our pentesters

Code Injection in Wave Term v0.12.2 allowing TCC Bypass

6.9

Medium

CVE-2025-12843

Published date:

12 dic 2025

Discovered by

Oscar Uribe

External pentesters

i-Educar 2.10.0 - Stored Cross-Site Scripting (XSS) in admin panel

4.8

Medium

CVE-2025-9638

Published date:

9 dic 2025

Discovered by

Marcelo Queiroz

Our pentesters

Frappe Helpdesk 1.14.0 — SQL Injection in dashboard get_dashboard_data

8.6

High

CVE-2025-10655

Published date:

9 dic 2025

Discovered by

Cristian Vargas

Our pentesters

Frappe CRM 1.53.1 — Multiple SQL Injections in Dashboard Controller

7.1

High

CVE-2025-11461

Published date:

26 nov 2025

Discovered by

Cristian Vargas

Our pentesters

OpenSearch 3.2.0 - Nested Boolean/Disjunction Asymmetric DoS

8.3

High

CVE-2025-9624

Published date:

25 nov 2025

Discovered by

Camilo Vera

Our pentesters

iStat Menus 7.10.4 - Local Privilege Escalation

8.5

High

CVE-2025-11921

Published date:

7 nov 2025

Discovered by

Oscar Uribe

Our pentesters

OpenSupports 4.11.0 — SSRF via test imap and smtp endpoints

6.9

Medium

CVE-2025-10695

Published date:

3 oct 2025

Discovered by

Cristian Vargas

Cargar más

Learn about our policy for disclosing advisories of vulnerabilities in third-party, open-source products.

Inicia tu prueba gratuita de 21 días

Descubre los beneficios de nuestra solución Hacking Continuo, de la que ya disfrutan empresas de todos los tamaños.

Inicia tu prueba gratuita de 21 días

Descubre los beneficios de nuestra solución Hacking Continuo, de la que ya disfrutan empresas de todos los tamaños.

Inicia tu prueba gratuita de 21 días

Descubre los beneficios de nuestra solución Hacking Continuo, de la que ya disfrutan empresas de todos los tamaños.

Las soluciones de Fluid Attacks permiten a las organizaciones identificar, priorizar y remediar vulnerabilidades en su software a lo largo del SDLC. Con el apoyo de la IA, herramientas automatizadas y pentesters, Fluid Attacks acelera la mitigación de la exposición al riesgo de las empresas y fortalece su postura de ciberseguridad.

Lee un resumen de Fluid Attacks

Suscríbete a nuestro boletín

Mantente al día sobre nuestros próximos eventos y los últimos blog posts, advisories y otros recursos interesantes.

SOC 2 Type II

SOC 3

Las soluciones de Fluid Attacks permiten a las organizaciones identificar, priorizar y remediar vulnerabilidades en su software a lo largo del SDLC. Con el apoyo de la IA, herramientas automatizadas y pentesters, Fluid Attacks acelera la mitigación de la exposición al riesgo de las empresas y fortalece su postura de ciberseguridad.

Suscríbete a nuestro boletín

Mantente al día sobre nuestros próximos eventos y los últimos blog posts, advisories y otros recursos interesantes.

Mantente al día sobre nuestros próximos eventos y los últimos blog posts, advisories y otros recursos interesantes.

SOC 2 Type II

SOC 3

Las soluciones de Fluid Attacks permiten a las organizaciones identificar, priorizar y remediar vulnerabilidades en su software a lo largo del SDLC. Con el apoyo de la IA, herramientas automatizadas y pentesters, Fluid Attacks acelera la mitigación de la exposición al riesgo de las empresas y fortalece su postura de ciberseguridad.

Suscríbete a nuestro boletín

Mantente al día sobre nuestros próximos eventos y los últimos blog posts, advisories y otros recursos interesantes.

Mantente al día sobre nuestros próximos eventos y los últimos blog posts, advisories y otros recursos interesantes.

SOC 2 Type II

SOC 3