Disclosed field reports
31 reviewed public disclosures. Severity is the source label, including Medium and Low. The card keeps the proof pattern and the fix, and leaves out payloads and private submissions.
Disclosed field reports index
- Command injection in a scientific analysis tool - P1 · National Aeronautics and Space Administration (NASA) - Vulnerability Disclosure Program · OS command injection
- Command-injection risk in a trajectory-subsetting service - P1 · National Aeronautics and Space Administration (NASA) - Vulnerability Disclosure Program · OS command injection
- Stored script execution through an upload surface - P2 · National Aeronautics and Space Administration (NASA) - Vulnerability Disclosure Program · Stored cross-site scripting through file upload
- Archive extraction path-traversal exposure - P2 · National Aeronautics and Space Administration (NASA) - Vulnerability Disclosure Program · Improper path restriction during archive extraction
- Local-device action exposure through DNS rebinding - P2 · SpaceX/Starlink · Cross-site request forgery combined with DNS rebinding
- Unauthenticated SQL-injection exposure in an archive interface - P1 · National Aeronautics and Space Administration (NASA) - Vulnerability Disclosure Program · SQL injection
- Blind SQL-injection signal in a public search surface - P1 · National Aeronautics and Space Administration (NASA) - Vulnerability Disclosure Program · Blind SQL injection
- Unsafe deserialization in a scientific-analysis project - P1 · National Aeronautics and Space Administration (NASA) - Vulnerability Disclosure Program · Insecure deserialization
- Unsafe input evaluation in an API validation path - P1 · National Aeronautics and Space Administration (NASA) - Vulnerability Disclosure Program · Unsafe evaluation of untrusted input
- Network-message length validation failure - P2 · National Aeronautics and Space Administration (NASA) - Vulnerability Disclosure Program · Stack-based buffer overflow
- Log4j remote code injection - critical; CVSS 10.0 · Apache · Injection through untrusted log data reaching a lookup-capable component
- Spring Framework remote code execution - critical; CVSS 9.8 · VMware / Spring · Improper neutralization of special elements in data binding
- MOVEit Transfer SQL injection - critical; CVSS 9.8 · Progress Software · SQL injection
- Apache ActiveMQ remote code execution - critical; CVSS 10.0 · Apache · Deserialization of untrusted data
- Malicious upstream code in xz Utils - critical; CVSS 10.0 · xz Utils project · Embedded malicious code in a software supply-chain release
- PAN-OS GlobalProtect command injection - critical; CVSS 9.8 · Palo Alto Networks · Command injection
- ConnectWise ScreenConnect authentication bypass - critical; CVSS 10.0 · ConnectWise · Authentication bypass using an alternate path or channel
- FortiOS out-of-bounds write - critical; CVSS 9.8 · Fortinet · Out-of-bounds write
- TeamCity authentication bypass - critical; CVSS 9.8 · JetBrains · Authentication bypass using an alternate path or channel
- PHP CGI argument injection - critical; CVSS 9.8 · PHP · OS command injection
- A leftover trip endpoint returned another rider's driver details - Medium (5.3) · Bykea · Insecure direct object reference
- A GraphQL tag mutation acted on another user's asset - Medium (5.3) · HackerOne · Insecure direct object reference
- A WebAuthn record could be updated from the public key - Low (3.1) · Nextcloud · Insecure direct object reference
- An OAuth redirect left the registered callback - High (7 ~ 8.9) · pixiv · OAuth redirect validation
- A private page was stored at a static-looking URL - Medium (5.0) · Algolia · Web cache deception
- A smuggled request was stored as a cached response - High (8.7) · PayPal · HTTP request smuggling
- An SSRF filter allowed a prefix that still maps inside - High (7.5) · arkadiyt-projects · Server-side request forgery
- Parallel requests passed a verification limit - High (7 ~ 8.9) · Tools for Humanity · Race condition
- An API reflected the caller's origin and allowed credentials - Medium (5.7) · Semrush · CORS misconfiguration
- A negative quantity changed the amount charged - Critical (9 ~ 10) · Upserve · Business logic errors
- An OAuth error on the AI Playground reached a connected MCP server - Low (0.1 ~ 3.9) · Cloudflare Public Bug Bounty · Reflected cross-site scripting