Skip to content

securelayer7/Research

Repository files navigation

SecureLayer7

SecureLayer7 Research


About

SecureLayer7's research team focuses on identifying, analyzing, and responsibly disclosing vulnerabilities across widely-used software. This repository serves as a centralized archive of our published CVE research, proof-of-concept exploits, and lab environments.


Published Research

# Published CVE ID Product Type Severity Analysis
1 2023-09-24 CVE-2023-38831 WinRAR RCE Critical Zero-Day RCE via DarkMe
2 2023-12-11 CVE-2023-22518 Atlassian Confluence Auth Bypass Critical Authentication Bypass
3 2024-01-10 CVE-2023-26360 Adobe ColdFusion RCE Critical Unauthenticated RCE
4 2024-01-30 CVE-2020-9496 / CVE-2023-49070 / CVE-2023-51467 Apache OFBiz RCE + Auth Bypass Critical Multiple Vulnerabilities
5 2024-03-11 CVE-2024-23897 Jenkins Arbitrary File Read Critical Arbitrary File Read
6 2024-05-24 CVE-2023-39143 PaperCut RCE High Remote Code Execution
7 2024-06-05 CVE-2024-27348 Apache HugeGraph RCE Critical Sandbox Bypass RCE
8 2024-06-19 CVE-2024-25065 Apache OFBiz Path Traversal High Auth Bypass via Path Traversal
9 2024-07-02 CVE-2024-31204 / CVE-2024-30270 Mailcow XSS + Path Traversal High XSS & Path Traversal
10 2024-08-01 CVE-2024-39877 Apache Airflow Code Execution High Jinja2 Template Injection
11 2024-08-22 CVE-2024-22263 Spring Cloud Data Flow Arbitrary File Write High Arbitrary File Writing
12 2024-09-26 CVE-2024-38856 Apache OFBiz RCE High File Read to RCE
13 2025-12-05 CVE-2025-55182 React / Next.js Prototype Pollution Critical Prototype Pollution
14 2025-12-21 CVE-2025-68613 n8n RCE (Expression Injection) Critical Expression Injection RCE
15 2026-02-04 CVE-2026-25049 n8n RCE Critical Remote Code Execution
16 2026-03-02 Pending IPVanish VPN (macOS) Local Privilege Escalation High macOS Privilege Escalation
17 2026-03-02 DeepChat (Electron) RCE via XSS / openExternal Critical openExternal RCE via XSS
18 2026-03-06 CVE-2026-22708 / CVE-2026-25253 OpenClaw Prompt Injection + Auth Bypass High ClawdBot VS Code Trojan & OpenClaw Risks
19 2026-03-19 CVE-2026-22729 Spring AI (PgVectorStore) JSONPath Injection High JSONPath Injection
20 2026-03-19 CVE-2026-22730 Spring AI (MariaDB Vector Store) SQL Injection High SQL Injection
21 2026-03-23 CVE-2026-24291 Windows Registry Privilege Escalation Critical RegPwn
22 2026-03-26 CVE-2024-54676 Apache OpenMeetings RCE Critical Deserialization RCE
23 2026-03-31 CVE-2025-59489 Unity Hub (macOS) DyLib Injection / TCC Bypass High TCC Bypass via DyLib Injection
24 2026-04-09 CVE-2024-52012 Apache Solr Path Traversal RCE Critical Zip Slip RCE
25 2026-04-20 CVE-2025-57738 Apache Syncope Groovy Injection RCE High Groovy Injection RCE

Contact

Website securelayer7.net
Blog blog.securelayer7.net
Twitter @securelayer7
Disclosure Coordinated 90-day responsible disclosure policy

All research is conducted responsibly. Vulnerabilities are reported to vendors before public disclosure.

About

Vulnerability Research & CVE Analysis by SecureLayer7

Resources

Stars

Watchers

Forks

Releases

No releases published

Packages

 
 
 

Contributors

Languages