faizal@security:~$

~/vulnerabilities$

CVE Discoveries

Security vulnerabilities discovered through responsible disclosure

CVE-2022-2170CriticalSSRFCVSS 9.8

Server-Side Request Forgery Vulnerability

Discovered a Server-Side Request Forgery vulnerability that allowed unauthenticated attackers to make arbitrary HTTP requests from the server, leading to internal service enumeration and cloud metadata access.

Enterprise SaaS Platform2022
CVE-2025-67436CriticalRCECVSS 9.1

Remote Code Execution Vulnerability

Identified an unsafe deserialization vulnerability in the API gateway's request transformation layer. Crafted payloads could achieve remote code execution on the gateway server.

Cloud API Gateway2025
CVE-2026-27127CriticalAuth BypassCVSS 9.4

Authentication Bypass via JWT Vulnerability

Identified a JWT algorithm confusion vulnerability where the application accepted HMAC-signed tokens using the RSA public key, allowing forging valid admin tokens.

Healthcare Platform2026
CVE-2025-68454HighIDORCVSS 8.6

Insecure Direct Object Reference

Found an Insecure Direct Object Reference in the user data export functionality. By manipulating the export request ID parameter, an authenticated user could download any other user's exported data.

FinTech Application2025
CVE-2026-25498HighXSSCVSS 7.5

Cross-Site Scripting Vulnerability

Discovered a stored Cross-Site Scripting vulnerability through SVG file uploads. Malicious SVG files with embedded JavaScript were rendered without sanitization.

Content Management System2026
CVE-2026-27129HighSSRFCVSS 7.2

Server-Side Request Forgery in Cloud Service

Exploited an SSRF in the PDF generation feature by injecting a crafted URL in the HTML template, allowing access to internal cloud metadata endpoints.

Document Processing Service2026