Published CVEs, advisories, and security research by Peyton Kennedy (p80n).
Browse the full inventory, including per-finding detail pages and talks: https://www.p80n.com/
| ID | Date | Project | CVSS | Links |
|---|---|---|---|---|
| — | 2026-08-08 | Dify | — | ENDOR-VUL-2026-0105 · Writeup · DEF CON 34 |
| — | 2026-08-08 | Kestra | 9.8 | ENDOR-VUL-2026-0202 · Writeup · DEF CON 34 |
| — | 2026-08-08 | Kestra | 9.8 | ENDOR-VUL-2026-02021 · Writeup · DEF CON 34 |
| — | 2026-08-08 | NocoBase | 9.9 | ENDOR-VUL-2026-16041 · Writeup · DEF CON 34 |
| — | 2026-08-08 | NocoBase | 8.7 | ENDOR-VUL-2026-16044 · Writeup · DEF CON 34 |
| — | 2026-08-08 | Langflow | — | ENDOR-VUL-2026-2601 · Writeup · DEF CON 34 |
| — | 2026-08-08 | Langflow | — | ENDOR-VUL-2026-26012 · Writeup · DEF CON 34 |
| GHSA-j77w-g4jj-hp99 | 2026-08-07 | gh-aw | 9.6 | ENDOR-VUL-2026-0906 |
| GHSA-9fpm-3445-2vx4 | 2026-08-04 | Langflow | 8.8 | ENDOR-VUL-2026-26011 · Writeup · DEF CON 34 |
| CVE-2026-73487 | 2026-07-29 | Flowise | 9.3 | ENDOR-VUL-2026-1704 · Writeup · DEF CON 34 |
| CVE-2026-73081 | 2026-07-17 | Activepieces | 8.7 | ENDOR-VUL-2026-30031 · Writeup · DEF CON 34 |
| CVE-2026-73083 | 2026-07-17 | Activepieces | 7.6 | ENDOR-VUL-2026-3003 · Writeup · DEF CON 34 |
| CVE-2026-55407 | 2026-07-01 | buffa | 6.3 | ENDOR-VUL-2026-2105 · Writeup |
| CVE-2026-41640 | 2026-04-22 | NocoBase | 7.5 | ENDOR-VUL-2026-16043 · Writeup · DEF CON 34 |
| CVE-2026-41641 | 2026-04-22 | NocoBase | 7.2 | ENDOR-VUL-2026-16042 · Writeup · DEF CON 34 |
| CVE-2026-30898 | 2026-04-17 | Apache Airflow | 8.8 | ENDOR-VUL-2026-0503 · Writeup · DEF CON 34 |
| CVE-2026-27959 | 2026-02-26 | Koa | 7.5 | ENDOR-VUL-2026-2301 · Writeup |
| CVE-2026-32060 | 2026-02-19 | OpenClaw | 8.7 | ENDOR-VUL-2026-04027 · Writeup |
| CVE-2026-26329 | 2026-02-18 | OpenClaw | 7.1 | ENDOR-VUL-2026-04026 · Writeup |
| CVE-2026-28476 | 2026-02-18 | OpenClaw | 6.3 | ENDOR-VUL-2026-04022 · Writeup |
| CVE-2026-29606 | 2026-02-18 | OpenClaw | 6.3 | ENDOR-VUL-2026-04024 · Writeup |
| CVE-2026-26319 | 2026-02-17 | OpenClaw | 7.5 | ENDOR-VUL-2026-04021 · Writeup |
| CVE-2026-26322 | 2026-02-17 | OpenClaw | 7.6 | ENDOR-VUL-2026-04025 · Writeup |
| GHSA-56f2-hvwg-5743 | 2026-02-17 | OpenClaw | 7.6 | ENDOR-VUL-2026-04023 · Writeup |
| CVE-2025-63662 | 2025-12-22 | GT Edge AI Platform | 7.5 | Writeup · BSides NoVA 2025 · CackalackyCon 2026 |
| CVE-2025-63663 | 2025-12-22 | GT Edge AI Platform | 7.5 | Writeup · BSides NoVA 2025 · CackalackyCon 2026 |
| CVE-2025-63664 | 2025-12-22 | GT Edge AI Platform | 7.5 | Writeup · BSides NoVA 2025 · CackalackyCon 2026 |
| CVE-2025-63665 | 2025-12-19 | GT Edge AI Platform | 9.8 | Writeup · BSides NoVA 2025 · CackalackyCon 2026 |
CVSS scores are CISA-ADP assessments where NVD analysis is still pending.
Reported and awaiting fix, under a 90+30 day disclosure policy.
| Reference | Project / Repository | Date Reported | Deadline Expires |
|---|---|---|---|
| None outstanding |
Records live in findings/, one folder each. The tables above are generated by
python -m tools.generate — edit the records, not the tables.
Before merging a finding written by someone else, or if you are wondering whether the disclosure clock is still running, read docs/maintenance.md: finding bodies render raw HTML by design, and GitHub disables the scheduled clock after 60 days of repository inactivity without reporting an error.