mitsec

Disclosure

CVEs & recognition

100+HOF Entries
2430+Vulns Reported
1100+P1 Critical
12+Years Exp
2025

CVE-2025-55182 Critical · CVSS 9.1

Next.js RSC — React Server Components deserialization leading to remote code execution.

2025

CVE-2025-29927 High · CVSS 7.5

Next.js — Middleware authorization bypass via crafted internal subrequest header.

2023

CVE-2023-38646 Critical · CVSS 9.8

Metabase — Pre-authentication remote code execution through the setup token endpoint.

2021

CVE-2021-3129 Critical · CVSS 9.8

Laravel / Ignition — Debug-mode file write chained to RCE via log poisoning.

Hall of Fame

APPLE
MICROSOFT
META
IBM
INTIGRITI
YESWEHACK
BUGCROWD
HACKERONE
T-MOBILE
SBB
TÜV RHEINLAND
HARMAN
↑↓ navigate↵ openesc close