Publicly disclosed vulnerabilities discovered by or reported to Fluid Attacks

Search by term

Search filters

Discovered by

All

Severity

All

Our pentesters

xmltodict 0.14.2 - XML Injection

6.9

Medium

CVE-2025-9375

Published date:

Sep 1, 2025

Discovered by

Camilo Vera

Our pentesters

Markdown-it 14.1.0 - Cross-site scripting (XSS)

6.9

Medium

CVE-2025-7969

Published date:

Aug 21, 2025

Discovered by

Camilo Vera

Our pentesters

Bunker Web 1.6.2 - Uncontrolled external site redirect

4.8

Medium

CVE-2025-8066

Published date:

Aug 15, 2025

Discovered by

Johan Giraldo

Our pentesters

KAP 3.6.0 - TCC Bypass

6.9

Medium

CVE-2025-7961

Published date:

Aug 14, 2025

Discovered by

Oscar Uribe

Our pentesters

Linkify 4.3.1 - Prototype Pollution & HTML Attribute Injection (XSS)

8.8

High

CVE-2025-8101

Published date:

Jul 25, 2025

Discovered by

Camilo Vera

Our pentesters

Calibre Web 0.6.24 - Blind Command Injection

5.9

Medium

CVE-2025-7404

Published date:

Jul 24, 2025

Discovered by

Johan Giraldo

Our pentesters

Calibre Web 0.6.24 - ReDoS

8.7

High

CVE-2025-6998

Published date:

Jul 24, 2025

Discovered by

Johan Giraldo

Our pentesters

XSS in Laundry allows to perform an Account Takeover

5.1

Medium

CVE-2025-52842

Published date:

Jul 2, 2025

Discovered by

Carlos Bello

Load more

Search by term

Search filters

Discovered by

All

Severity

All

Our pentesters

xmltodict 0.14.2 - XML Injection

6.9

Medium

CVE-2025-9375

Published date:

Sep 1, 2025

Discovered by

Camilo Vera

Our pentesters

Markdown-it 14.1.0 - Cross-site scripting (XSS)

6.9

Medium

CVE-2025-7969

Published date:

Aug 21, 2025

Discovered by

Camilo Vera

Our pentesters

Bunker Web 1.6.2 - Uncontrolled external site redirect

4.8

Medium

CVE-2025-8066

Published date:

Aug 15, 2025

Discovered by

Johan Giraldo

Our pentesters

KAP 3.6.0 - TCC Bypass

6.9

Medium

CVE-2025-7961

Published date:

Aug 14, 2025

Discovered by

Oscar Uribe

Our pentesters

Linkify 4.3.1 - Prototype Pollution & HTML Attribute Injection (XSS)

8.8

High

CVE-2025-8101

Published date:

Jul 25, 2025

Discovered by

Camilo Vera

Our pentesters

Calibre Web 0.6.24 - Blind Command Injection

5.9

Medium

CVE-2025-7404

Published date:

Jul 24, 2025

Discovered by

Johan Giraldo

Our pentesters

Calibre Web 0.6.24 - ReDoS

8.7

High

CVE-2025-6998

Published date:

Jul 24, 2025

Discovered by

Johan Giraldo

Our pentesters

XSS in Laundry allows to perform an Account Takeover

5.1

Medium

CVE-2025-52842

Published date:

Jul 2, 2025

Discovered by

Carlos Bello

Load more

Search by term

Search filters

Discovered by

All

Severity

All

Our pentesters

xmltodict 0.14.2 - XML Injection

6.9

Medium

CVE-2025-9375

Published date:

Sep 1, 2025

Discovered by

Camilo Vera

Our pentesters

Markdown-it 14.1.0 - Cross-site scripting (XSS)

6.9

Medium

CVE-2025-7969

Published date:

Aug 21, 2025

Discovered by

Camilo Vera

Our pentesters

Bunker Web 1.6.2 - Uncontrolled external site redirect

4.8

Medium

CVE-2025-8066

Published date:

Aug 15, 2025

Discovered by

Johan Giraldo

Our pentesters

KAP 3.6.0 - TCC Bypass

6.9

Medium

CVE-2025-7961

Published date:

Aug 14, 2025

Discovered by

Oscar Uribe

Our pentesters

Linkify 4.3.1 - Prototype Pollution & HTML Attribute Injection (XSS)

8.8

High

CVE-2025-8101

Published date:

Jul 25, 2025

Discovered by

Camilo Vera

Our pentesters

Calibre Web 0.6.24 - Blind Command Injection

5.9

Medium

CVE-2025-7404

Published date:

Jul 24, 2025

Discovered by

Johan Giraldo

Our pentesters

Calibre Web 0.6.24 - ReDoS

8.7

High

CVE-2025-6998

Published date:

Jul 24, 2025

Discovered by

Johan Giraldo

Our pentesters

XSS in Laundry allows to perform an Account Takeover

5.1

Medium

CVE-2025-52842

Published date:

Jul 2, 2025

Discovered by

Carlos Bello

Load more

Search by term

Search filters

Discovered by

All

Severity

All

Our pentesters

xmltodict 0.14.2 - XML Injection

6.9

Medium

CVE-2025-9375

Published date:

Sep 1, 2025

Discovered by

Camilo Vera

Our pentesters

Markdown-it 14.1.0 - Cross-site scripting (XSS)

6.9

Medium

CVE-2025-7969

Published date:

Aug 21, 2025

Discovered by

Camilo Vera

Our pentesters

Bunker Web 1.6.2 - Uncontrolled external site redirect

4.8

Medium

CVE-2025-8066

Published date:

Aug 15, 2025

Discovered by

Johan Giraldo

Our pentesters

KAP 3.6.0 - TCC Bypass

6.9

Medium

CVE-2025-7961

Published date:

Aug 14, 2025

Discovered by

Oscar Uribe

Our pentesters

Linkify 4.3.1 - Prototype Pollution & HTML Attribute Injection (XSS)

8.8

High

CVE-2025-8101

Published date:

Jul 25, 2025

Discovered by

Camilo Vera

Our pentesters

Calibre Web 0.6.24 - Blind Command Injection

5.9

Medium

CVE-2025-7404

Published date:

Jul 24, 2025

Discovered by

Johan Giraldo

Our pentesters

Calibre Web 0.6.24 - ReDoS

8.7

High

CVE-2025-6998

Published date:

Jul 24, 2025

Discovered by

Johan Giraldo

Our pentesters

XSS in Laundry allows to perform an Account Takeover

5.1

Medium

CVE-2025-52842

Published date:

Jul 2, 2025

Discovered by

Carlos Bello

Load more

Learn about our policy for disclosing advisories of vulnerabilities in third-party, open-source products.

Start your 21-day free trial

Discover the benefits of our Continuous Hacking solution, which organizations of all sizes are already enjoying.

Start your 21-day free trial

Discover the benefits of our Continuous Hacking solution, which organizations of all sizes are already enjoying.

Start your 21-day free trial

Discover the benefits of our Continuous Hacking solution, which organizations of all sizes are already enjoying.

Fluid Attacks' solutions enable organizations to identify, prioritize, and remediate vulnerabilities in their software throughout the SDLC. Supported by AI, automated tools, and pentesters, Fluid Attacks accelerates companies' risk exposure mitigation and strengthens their cybersecurity posture.

Subscribe to our newsletter

Stay updated on our upcoming events and latest blog posts, advisories and other engaging resources.

© 2025 Fluid Attacks. We hack your software.

Fluid Attacks' solutions enable organizations to identify, prioritize, and remediate vulnerabilities in their software throughout the SDLC. Supported by AI, automated tools, and pentesters, Fluid Attacks accelerates companies' risk exposure mitigation and strengthens their cybersecurity posture.

Subscribe to our newsletter

Stay updated on our upcoming events and latest blog posts, advisories and other engaging resources.

© 2025 Fluid Attacks. We hack your software.

Fluid Attacks' solutions enable organizations to identify, prioritize, and remediate vulnerabilities in their software throughout the SDLC. Supported by AI, automated tools, and pentesters, Fluid Attacks accelerates companies' risk exposure mitigation and strengthens their cybersecurity posture.

Subscribe to our newsletter

Stay updated on our upcoming events and latest blog posts, advisories and other engaging resources.

© 2025 Fluid Attacks. We hack your software.