Repo for discovered vulnerabilities & corresponding CVEs
| CVE ID | Year | Severity | Description | Write-up |
|---|---|---|---|---|
| CVE-2021-43778 | 2021 | 🔴 Critical | GLPi Path Traversal Arbitrary File Read | Details |
| CVE-2021-43779 | 2021 | 🔴 Critical | GLPi Command Injection RCE | Details |
| CVE-2022-25485 | 2022 | 🟠 HIGH | Cuppa CMS Local File Inclusion | Details |
| CVE-2022-25486 | 2022 | 🟠 HIGH | Cuppa CMS Local File Inclusion | Details |
| CVE-2022-34121 | 2022 | 🟠 HIGH | Cuppa CMS Local File Inclusion | Details |
| CVE-2022-43015 | 2022 | OpenCats ATS Reflected XSS | Details | |
| CVE-2022-43016 | 2022 | OpenCats ATS Reflected XSS | Details | |
| CVE-2022-43017 | 2022 | OpenCats ATS Reflected XSS | Details | |
| CVE-2022-43018 | 2022 | OpenCats ATS Reflected XSS | Details | |
| CVE-2022-43019 | 2022 | 🔴 Critical | OpenCats ATS Insecure Deserialization RCE | Details |
| CVE-2022-43020 | 2022 | 🟠 HIGH | OpenCats ATS SQL injection | Details |
| CVE-2022-43021 | 2022 | 🟠 HIGH | OpenCats ATS SQL injection | Details |
| CVE-2022-43022 | 2022 | 🟠 HIGH | OpenCats ATS SQL injection | Details |
| CVE-2022-43023 | 2022 | 🟠 HIGH | OpenCats ATS SQL injection | Details |
| CVE-2023-35133 | 2023 | 🟠 HIGH | Moodle LMS Server-Side Request Forgery | Details |
| Referrer-Policy research | 2024 | N/A | Google Chrome Referrer-Policy override | Blog |
| XSS research | 2024 | N/A | Weaponizing lesser known event handlers for XSS | Blog |
| CVE-2025-42615 | 2025 | 🟠 HIGH | Vulnerability-Lookup MFA Bypass | Details |
| CVE-2025-42616 | 2025 | 🟠 HIGH | Vulnerability-Lookup Multiple CSRF issues | Details |
| CVE-2025-42620 | 2025 | 🟠 HIGH | Vulnerability-Lookup DOM-based Stored XSS | Details |
| CVE-2026-40177 | 2026 | 🔴 Critical | Ajenti Control Panel Password Authentication bypass | Details |
| CVE-2026-40178 | 2026 | 🟠 HIGH | Ajenti Control Panel Multi Factor Authentication bypass | Details |