Disclosure
CVEs & recognition
100+HOF Entries
2430+Vulns Reported
1100+P1 Critical
12+Years Exp
2025
CVE-2025-55182 Critical · CVSS 9.1
Next.js RSC — React Server Components deserialization leading to remote code execution.
2025
CVE-2025-29927 High · CVSS 7.5
Next.js — Middleware authorization bypass via crafted internal subrequest header.
2023
CVE-2023-38646 Critical · CVSS 9.8
Metabase — Pre-authentication remote code execution through the setup token endpoint.
2021
CVE-2021-3129 Critical · CVSS 9.8
Laravel / Ignition — Debug-mode file write chained to RCE via log poisoning.
Hall of Fame
APPLE
MICROSOFT
META
IBM
INTIGRITI
YESWEHACK
BUGCROWD
HACKERONE
T-MOBILE
SBB
TÜV RHEINLAND
HARMAN