000-dayHighPublic
Vaultwarden 1.37.3 defaults IP_HEADER to X-Real-IP and IP_HEADER_TRUSTED_PROXIES to local. Any non-global TCP peer is treated as a reverse proxy, so a client X-Real-IP becomes the login rate-limit key. Stock Docker published-port NAT is RFC1918. Unique headers never share a burst. 2FA after a correct password still runs. No CVE yet.
02 Oct 2026Vaultwarden
Read analysis→010-dayHighPublic
Bitwarden Server 2026.9.2 lite on MariaDB/Postgres/SQLite nulls the caller UserId before attaching a new org cipher to collections. A confirmed member can plant a decryptable vault item into a collection they cannot write. Members sync it as a shared login. MSSQL/Dapper keeps the caller id. No CVE yet.
02 Oct 2026Bitwarden
Read analysis→02N-dayCVE-2026-19445CriticalPublic
CPython ssl servers that mint an SSLContext per connection, set sni_callback, and assign sslobj.context to a different context can drop the original SSLContext while OpenSSL still holds a borrowed pointer. A second ClientHello (HelloRetryRequest is enough) consults it. Handshake continues. Crash window. Labbed on 3.14.7.
01 Oct 2026Python Software Foundation
Read analysis→03N-dayCVE-2026-19553HighPublic
CPython ssl.SSLContext.wrap_bio() did not require server_hostname when check_hostname is set. SSLObject silently skips identity checks. The chain verifies. The name does not. wrap_socket already raised. asyncio turns an empty hostname into None and then wrap_bio. Labbed on 3.14.7.
01 Oct 2026Python Software Foundation
Read analysis→040-dayHighPublic
GitLab 19.4.1 UrlBlocker blocks exact 0.0.0.0 and 127.0.0.0/8, not the rest of 0.0.0.0/8. A Maintainer webhook at http://0.0.0.1/ reaches worker loopback with local-requests off. GitLab stores 8 KB of the body. No CVE yet.
01 Oct 2026GitLab
Read analysis→050-dayHighPublic
GitLab 19.4.1 GitHub Enterprise import skips ImportService IP pin. fetch_as_mirror defaults resolved_address to empty. Gitaly git-fetches the clone hostname again. Attacker objects land in the imported project. No CVE yet.
01 Oct 2026GitLab
Read analysis→060-dayHighPublic
GitLab 19.4.1 Gitea HTTPS import throws away the IP-pinned URI and reconnects to the original hostname. Rebind that name to loopback and Faraday GETs it. Repo-list JSON comes back on status.json. HTTP imports keep the pin. No CVE yet.
01 Oct 2026GitLab
Read analysis→070-dayHighPublic
MsQuic v2.6.1 default client treats a compatible-VN long header as a version switch before AEAD, recreates Initial keys, then either never reverts or restores only the version number. One UDP datagram from the server 4-tuple stops the handshake. No CVE yet.
30 Sept 2026Microsoft
Read analysis→080-dayCriticalPublic
SONiC gNMI still passes --client_auth cert as a fail-closed default, then unsets cert when ca_crt is empty. authenticate() treats empty UserAuth as success. Native and translib writes are compiled in. SmartSwitch DPU with no certs is remote on :8080. Default ToR is loopback. No CVE yet.
30 Sept 2026SONiC
Read analysis→090-dayHighPublic
n8n 2.42.0 Databricks Genie getSpace concatenates spaceId with no toPathSegment. Untrusted webhook input becomes GET /api/2.0/secrets/get under the workspace token. Sibling of GHSA-89p4 / GHSA-rqch. No CVE yet.
29 Sept 2026n8n
Read analysis→100-dayHighPublic
n8n 2.42.0 Function / FunctionItem / LangChain Code still run JS via leftover vm2 NodeVM in the main process. Palette hidden is not an ACL. Code v2 already uses the task-runner child. No CVE yet.
29 Sept 2026n8n
Read analysis→110-dayHighPublic
Uptime Kuma 2.5.5 Socket.IO setup on first-run COUNTs users, bcrypts, then INSERTs. Username is UNIQUE only. Concurrent unauth clients can insert a hidden second admin, then disableAuth auto-logins as user id 1. No CVE yet.
29 Sept 2026Uptime Kuma
Read analysis→120-dayMediumPublic
Gitea 1.27.3 OpenWithClient still implements file:// with os.Open. Operator restore of an untrusted dump rewrites release DownloadURL to file:// under the dump. os.Open follows a dump symlink. Not live-migrate LFI. No CVE yet.
29 Sept 2026Gitea
Read analysis→130-dayMediumPublic
Gitea 1.27.3 artifact v4 parseProtobufBody does io.ReadAll with no cap. Job-summary on the same instance already LimitReaders at 1 MiB. A running Actions job token can POST a 12 MiB CreateArtifact. Not process-kill. No CVE yet.
29 Sept 2026Gitea
Read analysis→140-dayMediumPublic
Gitea 1.27.3 PUT /api/v1/user/following/{username} skips IsUserVisibleToViewer. Follow of a hidden user is 204. Unknown names 404. GET /users/{name} already 404s hidden users. Status-class oracle only. No CVE yet.
29 Sept 2026Gitea
Read analysis→150-dayMediumPublic
Gitea 1.27.3 GetStargazers and GetWatchers omit isUserVisibleToViewerCond. A limited user who starred a public repo appears in unauth JSON while GET /users/{name} is 404. Follower lists already filter. No CVE yet.
29 Sept 2026Gitea
Read analysis→160-dayMediumPublic
Gitea 1.27.3 POST /api/v1/orgs has no rejectPublicOnly. A public-only PAT with write:organization creates a private organization. The same token cannot create a private user repository. No CVE yet.
29 Sept 2026Gitea
Read analysis→170-dayHighPublic
Gitea 1.27.3 reservedIPNets still omits RFC 6890 0.0.0.0/8. A signed-in user can webhook http://0.0.0.1 and read the HTTP body from hook history. 127.0.0.1 on the same port is denied. No CVE yet.
29 Sept 2026Gitea
Read analysis→180-dayHighPublic
Hyperswitch 2026.09.21.0 POST /payouts/{id}/confirm with api-key pk_ only requires client_secret present, not equal to payouts.client_secret. Confirm body is PayoutCreateRequest so amount is written before connector routing. Payments confirm still binds (IR_09). No CVE yet.
28 Sept 2026Juspay
Read analysis→190-dayHighPublic
Hyperswitch 2026.09.21.0 POST /webhooks/{merchant_id}/worldpayxml. Worldpayxml verify_webhook_source returns Ok(true). incoming.rs HandleResponse without PSync. lastEvent SETTLED maps to Charged. Dummy XML. No CVE yet.
28 Sept 2026Juspay
Read analysis→200-dayHighPublic
Lago v1.53.0 POST /webhooks/stripe/:org verifies the attacker org secret. metadata.payment_type=one-time then Invoice.find_by(id:) with no organization_id. handle_missing_payment is scoped. Dummy event. No CVE yet.
26 Sept 2026Lago
Read analysis→210-dayCriticalPublic
Lago v1.53.0 acceptInvite has no login. register_from_invite loads the user by invite email. If that account already has memberships, the posted password is ignored and a user-scoped JWT is issued. Inviter already has the token. No CVE yet.
26 Sept 2026Lago
Read analysis→220-dayHighPublic
OpenCart 4.1.0.4 reward.save unsets session.reward and never payment_method. coupon.save does. Apply points, pick Free Checkout, clear points, confirm writes catalog total, free_checkout.confirm does not recheck. No CVE yet.
26 Sept 2026OpenCart
Read analysis→230-dayCriticalPublic
PrestaShop 9.1.5 FO password recovery stamps sha1(time() . id_customer . '-' . secure_key). Order confirmation key= is that secure_key. Forgot POST writes the token even if mail fails. No mailbox. No CVE yet.
26 Sept 2026PrestaShop
Read analysis→240-dayHighPublic
Magento 2.4.8-p5 Instant Purchase copies every POST field into the buyRequest because $knownRequestParams is a list and isset() looks for keys. Checkout RequestInfoFilter strips custom_price. Instant Purchase does not. Quote Processor setCustomPrice. Lab charged 0.01 against catalog 99.99. No CVE yet.
26 Sept 2026Adobe
Read analysis→25NotesInfoPublic
The bounty queue is a sewer of AI-generated reports. I have stopped filing the bugs that matter. I write the analysis, release a public PoC, and post the link the same day. If you are holding one, do the same thing.
26 Sept 2026n/a (disclosure policy)
Read analysis→260-dayHighPublic
v1.27.3 closed the 2026 GHSA wave. Two unpublished bugs still lab on that tag: GET /api/v1/user/keys/{id} has no owner check, and git clone still follows HTTP redirects after a one-shot allow-list. Not unauthenticated RCE. CVE pending.
26 Sept 2026Gitea
Read analysis→27N-dayCVE-2026-61628HighPublic
nginx-ignition 2.41.0 registers POST /api/users/onboarding/finish as anonymous. The handler checks OnboardingCompleted, then Save()s a user with Users=READ_WRITE and returns a JWT. No lock. A virgin instance, or a race that mints two admins. Patched in 2.41.1.
22 Sept 2026lucasdillmann
Read analysis→28MalwareHighPublic
Two still-open PRs against shadcn-ui/ui carry the same NullReceiver loader OSM tracks as PolinRider. Same Ethereum wallet, live C2 in a zero-value transfer. One PR also drops Fake Font on folderOpen. Static only. I did not run the implant or talk to the C2.
20 Sept 2026n/a (PolinRider / NullReceiver cluster)
Read analysis→290-dayHighPublic
phpMyAdmin 5.2.3 CustomServer never verifies the WebAuthn assertion signature. After the MySQL password, a forged webauthn_request_response that matches challenge, origin, rpIdHash, and user-present is enough. Default tarball. No CVE yet.
20 Sept 2026phpMyAdmin
Read analysis→30N-dayCVE-2026-77635CriticalPublic
CakePHP FunctionsBuilder::jsonValue on PostgresDriver interpolates $jsonPath into JSONB_PATH_QUERY. quoteIdentifier is not a bind. The lab passes GET path into jsonValue. Not WordPress. Fixed in 5.2.15.
19 Sept 2026CakePHP
Read analysis→31N-dayCVE-2026-79752CriticalPublic
CakePHP FunctionsBuilder::cast splices $dataType into SQL as a literal. extract, datePart, and dateAdd do the same for $part and $unit. The lab passes GET type into cast. Not WordPress. Fixed in 5.2.14 and siblings.
19 Sept 2026CakePHP
Read analysis→32N-dayCVE-2026-81294CriticalPublic
Authorizer 3.15.1 GitHub OAuth2 takes emails[] without checking verified. Generic OAuth2 has the same hole. An unverified email that matches an admin is a WordPress session. 3.15.2 filters empty verified.
19 Sept 2026Paul Ryan
Read analysis→33N-dayCVE-2026-81648CriticalPublic
CryptoPayment Gateway 1.2.2 vendor/cryptd/ajax.php is a direct PHP endpoint. It defines crpay_security_error() and never calls it. delete-file concatenates __DIR__/uploads with file_name. Five .. reaches wp-content. No public patch.
19 Sept 2026Granwill
Read analysis→34N-dayCVE-2026-13447CriticalPublic
MStore API 4.18.4 FirebasePhoneAuthHelper::verify_id_token checks alg, kid, aud, and iss, then returns phone_number. It never calls openssl_verify. Forge a JWT, impersonate a phone, get an admin cookie. 4.21.1 verifies the signature.
19 Sept 2026inspireUI
Read analysis→35N-dayCVE-2026-19952HighPublic
Frontend Admin 3.29.12 move_folders concatenates uploads/basedir with a merge-tagged directory name. [acf:post_title] is the POST title. ../ walks out of uploads and unlinks index.php. Public form, harvested nonce. 3.29.13 adds get_safe_upload_dir.
19 Sept 2026DynamiApps
Read analysis→36N-dayCVE-2026-75816CriticalPublic
Frontend Admin 3.29.11 skips edit_post when the object id is the string user_1. pre_update_value then wp_update_user's that user's email with no capability check. Unauthenticated form_submit. Password reset is the rest.
19 Sept 2026DynamiApps
Read analysis→37N-dayCVE-2026-18937CriticalPublic
Broken Link Checker 2.4.11 merges every GET key into $wp->query_vars on plain permalinks. WP::register_globals copies those keys into $GLOBALS. Overwrite $shortcode_tags, render a shortcode, call_user_func. Classic theme. Unauthenticated.
19 Sept 2026WPMU DEV
Read analysis→38N-dayCVE-2026-45140CriticalPublic
Chamilo 2.0.0 CStudio big-upload.php takes GET key with no sanitization and no login. fopen appends php://input onto cacheDir plus that key. Traversal into public/ is a web file. The GHSA did not name the path.
18 Sept 2026chamilo
Read analysis→39N-dayCVE-2026-75827HighPublic
Grav before 2.0.15 allowlists Class::method dynamic-data providers and denylists bare functions. error_log is not on the denylist. A form data-options@ directive appends attacker bytes to a web path. Page-edit.
18 Sept 2026getgrav
Read analysis→40N-dayCVE-2026-82226CriticalPublic
Tickera 3.6.0.2 maybe_unserialize()s attendee owner_data *_post_meta in create_order. Cart nonce, cookie, free ticket, then process-payment. Objects run. Unauthenticated. Patched in 3.6.0.3.
18 Sept 2026Tickera
Read analysis→41N-dayCVE-2026-84753CriticalPublic
Mail Mint 1.31.0 stores extra form fields as contact meta, then maybe_unserialize()s them. Objects run before the is_array discard. The function is named safe_unserialize_meta. Unauthenticated. Two POSTs.
18 Sept 2026WPFunnels
Read analysis→42N-dayCVE-2026-77991CriticalPublic
JEM 5.0.0's CSS manager writes whatever filename the administrator hands it. resolveSourceFile blocks .. and cleans the path. It does not require .css. A PHP file under media/com_jem/css is the bug. Unauthenticated POST is not.
18 Sept 2026joomlaeventmanager.net
Read analysis→43N-dayCVE-2026-12793CriticalPublic
JetFormBuilder 3.6.2 accepts any post id as a form. parse_blocks on a regular post plus a Register User action is an administrator. The default submit hook is not the router. A 200 with a WordPress theme is not the bug.
18 Sept 2026Crocoblock
Read analysis→44N-dayCVE-2026-87796CriticalPublic
Multi Uploader for Gravity Forms 1.1.9 copies a chunked upload before it validates the type. The advisory names a PHP method. The HTTP action is something else. A 200 with a WordPress theme is not the bug.
18 Sept 2026sh1zen
Read analysis→45NotesCVE-2021-41773InfoPublic
32 GB unified memory is enough for an abliterated Qwen that will read a lab CVE, name the sink, and write a PoC. The catch is which Qwen. A 35B MoE OffSec fine-tune runs at 16.6 tok/s on this Air. Dense 27B writes a prettier script and takes eleven minutes to do it.
12 Sept 2026n/a (local llama.cpp eval)
Read analysis→46Series0-dayHighPublic
Spicy malware. Full kill-chain implant: exploit, escalate, pivot, poison, C2. Windows 10/11 x64 source on GitHub, released as-is and slightly broken on purpose.
04 Sept 2026n/a (private implant kit, source released)
Read series→47SeriesN-dayCVE-2024-21762CriticalPublic
I found a private FortiGate SSL-VPN kit in the wild and released it. 179 working clients, two public CVEs, 53 SKUs. The tree is on GitHub.
31 Aug 2026Fortinet
Read series→48Series0-dayHighPublic
YogSotho hid a Fortinet 0-day hunter behind two locks and a TESO homage. I opened the GoFile share with OSINT plus the listing API, then re-keyed a local copy of the ELF gate without recovering his passphrase. This is the map.
29 Aug 2026Fortinet
Read series→49MalwareCVE-2019-5736InfoPublic
Linux will run a program that has no name. I went looking for folklore and found memfd_create: anonymous RAM, an ELF, and an exe symlink that has been willing to testify the entire time. Stock Debian still leaves the door open.
20 Aug 2026Linux kernel / Debian
Read analysis→50MalwareHighPublic
Found beacon.exe in the wild. The filename begged for Sliver. The pclntab and the C2 URLs said otherwise: a privately built Go implant with HTTPS plus framed TCP, AES-256-GCM, and a full post-ex menu. Not Sliver. Not Cobalt. Not stock Adaptix.
19 Aug 2026n/a (private C2; callback on PEG TECH / AROSSCLOUD)
Read analysis→51N-dayInfoPublic
I opened plugandpwn.com with a Rubber Ducky on the desk. The mapping took ten minutes. Different USB device. Different primitive. Different trust boundary. Here is the teaching cut.
18 Aug 2026n/a (HID vs Windows PnP)
Read analysis→