You're viewing a live demo with sample data. Sign up to connect your own assets.
TrawlSec Sign up

Findings

Sample threat intel matches for TrawlSec's demo team.

CVE-2025-11071: lodash template() arbitrary code execution via untrusted template strings

New lodash · 2026-09-18

lodash.template() compiles untrusted input into executable JavaScript when the caller doesn't pre-sanitize template data.

https://nvd.nist.gov/vuln/detail/CVE-2025-11071

Sign up to disposition findings like this one.

CVE-2025-32728: OpenSSH sshd DoS via crafted authentication banner

New openssh · 2026-09-17

An oversized authentication banner can exhaust worker memory before authentication completes.

https://euvd.enisa.europa.eu/vulnerability/EUVD-2025-32728

Sign up to disposition findings like this one.

CVE-2025-27151: Redis ACL bypass via crafted MULTI/EXEC transaction

New redis · 2026-09-16

Under specific ACL configurations, a queued command inside a transaction can bypass command permission checks.

https://nvd.nist.gov/vuln/detail/CVE-2025-27151

Sign up to disposition findings like this one.

CVE-2025-53859: nginx QUIC module memory disclosure under malformed packets

New nginx · 2026-09-15

A malformed QUIC packet can trigger an out-of-bounds read in the HTTP/3 module, potentially disclosing worker process memory.

https://euvd.enisa.europa.eu/vulnerability/EUVD-2025-53859

Sign up to disposition findings like this one.

CVE-2024-27980: Node.js command injection via crafted batch filenames on Windows

Ignored node:20-alpine · 2026-09-14

Affects Windows batch-file execution only. Our node:20-alpine containers run on Linux, so the risk is accepted without further action.

https://nvd.nist.gov/vuln/detail/CVE-2024-27980

Sign up to disposition findings like this one.

CVE-2024-10977: PostgreSQL libpq error message truncation

False positive postgresql · 2026-09-13

Reviewed against our deployment: we do not use libpq client-side error parsing in the affected code path, and the server is not exposed to untrusted clients.

https://nvd.nist.gov/vuln/detail/CVE-2024-10977

Sign up to disposition findings like this one.

GHSA-jf85-cpcp-j695: Prototype pollution in lodash.merge

Investigating lodash · 2026-09-12

Crafted input to lodash.merge can pollute Object.prototype, potentially enabling denial of service or property injection downstream.

https://github.com/advisories/GHSA-jf85-cpcp-j695

Sign up to disposition findings like this one.

CVE-2024-31449: Redis Lua sandbox escape via bit library

Investigating redis · 2026-09-11

A stack buffer overflow in the Lua bit library bundled with Redis can be exploited from a Lua script to achieve remote code execution.

https://euvd.enisa.europa.eu/vulnerability/EUVD-2024-31449

Sign up to disposition findings like this one.

CVE-2024-6387: OpenSSH regreSSHion signal handler race condition

Confirmed openssh · 2026-09-10 · JIRA-4790

A signal handler race condition in sshd allows unauthenticated remote code execution as root on glibc-based Linux systems.

https://nvd.nist.gov/vuln/detail/CVE-2024-6387

Sign up to disposition findings like this one.

CVE-2025-1974: nginx ingress-nginx admission controller allows unauthenticated RCE

Confirmed nginx · 2026-09-09 · JIRA-4821

A crafted admission review request can inject arbitrary paths into the nginx template, leading to remote code execution in the ingress controller pod.

https://nvd.nist.gov/vuln/detail/CVE-2025-1974

Sign up to disposition findings like this one.

Title Asset Status Date
lodash New 2026-09-18
openssh New 2026-09-17
redis New 2026-09-16
nginx New 2026-09-15
node:20-alpine Ignored 2026-09-14
postgresql False positive 2026-09-13
lodash Investigating 2026-09-12
redis Investigating 2026-09-11
openssh Confirmed 2026-09-10
nginx Confirmed 2026-09-09