Security Advisories
Complete history of vulnerabilities disclosed by our research team, from 2012 to the present day.
2026 1 advisory
2020 1 advisory
2018 5 advisories
2017 19 advisories
- 2017-001BlueRiver Mura CMS vulnerable to Stored Cross Site Scripting Attacks via rb parameter
- 2017-002Paypal.com self-XSS Vulnerability
- 2017-003My AOL | Today's News vulnerable to Path Traversal
- 2017-004XSS Reflected found in the portuguese ESET ecommerce
- 2017-005XSS Reflected found in the ESET UK Partner Login page
- 2017-006SQL injection found in the portuguese ESET ecommerce
- 2017-007nod32.com.br from Nod32 Brasil is vulnerable to Time Based SQL
- 2017-008XSS Reflected found in the SAP events portal
- 2017-009Path Traversal found in the External Documentation Nokia Repository
- 2017-010Google Earth 'QtWebKit4' NULL Pointer Dereference Vulnerability
- 2017-011XSS Reflected found in the Microsoft app Source
- 2017-012XSS Reflected found in the Microsoft Azure Marketplace website
- 2017-013XSS Reflected found in the Microsoft Sign Up portal
- 2017-014XSS Reflected found in the AT&T Reward Center portal
- 2017-015XSS Reflected found in the AT&T Reward Center portal
- 2017-016XSS Reflected found in the Vodafone German Shop
- 2017-017XSS Reflected found in a Vodafone Deutschland website
- 2017-018XSS Reflected found in a Vodafone Deutschland website
- 2017-019Stored XSS found in Google Earth
2016 2 advisories
2015 1 advisory
2014 1 advisory
2013 13 advisories
- 2013-001CSRF vulnerability in LinkedIn
- 2013-002Reflected XSS in Asteriskguru Queue Statistics
- 2013-003XSS vulnerability in LinkedIn
- 2013-004Reflected XSS in the view attachment message process of Atmail WebMail <= v7.0.2
- 2013-005LinkedIn social network is affected by Persistent Cross-Site Scripting vulnerability
- 2013-006Multiple Reflected XSS vulnerabilities in LinkedIn Investors
- 2013-009Multiple Vulnerabilities in Telaen <= 1.3.0
- 2013-011HTTP Response Splitting Vulnerability in WebCollab <= v3.30
- 2013-012Multiple Full Path Disclosure Vulnerabilities in TinyWebGallery <= v1.8.9
- 2013-014Multiple reflected XSS vulnerabilities in Atmail WebMail
- 2013-016CSRF vulnerability in LinkedIn
- 2013-017SQL Injection vulnerability in "Project'Or RIA" allow arbitrary access to the database and the file system
- 2013-018Multiple XSS vulnerabilities in "Project'Or RIA"