| [ICO] | Name | Published | CVSS | Description |
|---|---|---|---|---|
| [DIR] | 2026-05-28 | 6.5 | Photo Gallery by 10Web—SQL Injection | |
| [TXT] | ├─ cve.org.url | 2026-05-28 | - | Official CVE Record |
| [TXT] | ├─ nvd.nist.gov.url | 2026-06-17 | - | NIST National Vulnerability Database |
| [TXT] | └─ wordfence.url | 2026-05-28 | - | CNA publication — Wordfence |
| [DIR] | 2026-08-01 | 6.4 | GenerateBlocks—Stored Cross-Site Scripting / Dynamic Tag Injection | |
| [TXT] | ├─ cve.org.url | 2026-08-01 | - | Official CVE Record |
| [TXT] | ├─ nvd.nist.gov.url | 2026-08-03 | - | NIST National Vulnerability Database |
| [TXT] | └─ wordfence.url | 2026-08-01 | - | CNA publication — Wordfence |
| [DIR] | 2026-03-04 | 5.4 | Enable Media Replace—Missing Authorization / Arbitrary Attachment Change | |
| [TXT] | ├─ cve.org.url | 2026-03-04 | - | Official CVE Record |
| [TXT] | ├─ nvd.nist.gov.url | 2026-06-17 | - | NIST National Vulnerability Database |
| [TXT] | └─ wordfence.url | 2026-03-04 | - | CNA publication — Wordfence |
| [DIR] | 2026-03-13 | 5.3 | Really Simple SSL—Broken Access Control / Missing Authorization | |
| [TXT] | ├─ cve.org.url | 2026-03-13 | - | Official CVE Record |
| [TXT] | ├─ nvd.nist.gov.url | 2026-06-17 | - | NIST National Vulnerability Database |
| [TXT] | └─ patchstack.url | 2026-03-13 | - | CNA publication — Patchstack |
| [DIR] | 2026-04-08 | 4.7 | Hide My WP Ghost—Open Redirect | |
| [TXT] | ├─ cve.org.url | 2026-04-08 | - | Official CVE Record |
| [TXT] | ├─ nvd.nist.gov.url | 2026-07-24 | - | NIST National Vulnerability Database |
| [TXT] | └─ patchstack.url | 2026-04-08 | - | CNA publication — Patchstack |
| [DIR] | 2026-04-10 | 4.3 | Download Manager—Missing Authorization / Media File Protection Removal | |
| [TXT] | ├─ cve.org.url | 2026-04-10 | - | Official CVE Record |
| [TXT] | ├─ nvd.nist.gov.url | 2026-06-17 | - | NIST National Vulnerability Database |
| [TXT] | └─ wordfence.url | 2026-04-10 | - | CNA publication — Wordfence |
I research vulnerabilities in web application surfaces, with a focus on responsible disclosure, technical validation, and maintaining a clean public record of published findings.
Expand an entry above for the official CVE record, the NVD entry, and the publishing CNA advisory. The Published column shows the disclosure/publication date for each finding; dates inside expanded entries correspond to the linked records.
Research is conducted with a responsible disclosure approach prior to publication.
This server keeps standard access logs: IP address, the approximate location and network operator derived from it, connection and browser characteristics as reported by your client, the page requested, and the referring page. Logs are used for traffic analysis and abuse prevention, are never shared with third parties, and are deleted after 90 days. No cookies, no advertising, no third-party analytics, and no tracking scripts run in your browser.