A collection of CVE disclosures and security patches by Stalin S.
- Reported — vulnerabilities discovered and reported by Stalin S.
- Patched — security issues where Stalin S coordinated and applied the fix.
CVEs that were discovered and reported by Stalin S.
| CVE | Description | Severity |
|---|---|---|
| CVE-2026-29905 | Kirby CMS Persistent DoS via Malformed Image Upload | Medium |
| CVE-2026-30081 | Quantum Networks QN-I-470 Cleartext Credential Transmission | Pending |
| CVE-2026-41037 | Missing Rate Limiting (Quantum Networks Router) | High (8.7) |
| CVE-2026-41039 | Information Disclosure (Quantum Networks Router) | High (8.7) |
| CVE-2026-42290 | protobufjs pbts Command Injection via Unsanitized File Paths |
High |
| CVE-2026-45152 | uniget Command Injection via Unsafe tool.Check Execution |
High |
| CVE-2026-55061 | uniget CLI Command Injection via EDITOR Environment Variable | Moderate |
| CVE-2026-55062 | uniget CLI Path Traversal via Hook Filename | Moderate |
| CVE-2026-59924 | Arbitrary File Read via Path Traversal (Mistune) | Medium (5.9) |
| CVE-2026-9506 | Path Traversal Vulnerability (Webkul Bagisto) | High (8.7) |
CVEs where Stalin S fixed the security issue.
| CVE | Description | Severity |
|---|---|---|
| CVE-2026-32138 | API Key Exposure (Nexulean Website) | High |
| CVE-2026-41575 | DOM-Based XSS (IP Reputation Checker) | Moderate |
| CVE-2026-41900 | RCE via Sandbox Escape (OpenLearnX) | High |
| CVE-2026-44720 | Authentication Bypass via JWT Signature Verification Disabled (OpenLearnX) | Moderate |
| CVE-2026-48097 | PATH Injection Leading to Arbitrary Command Execution in NexTOR IP Changer | High |
| CVE-2026-48098 | Unsafe Use of sudo and shell=True in NexTOR IP Changer | High |