Investigate real vulnerabilities with AI guidance. Every major CVE is MITRE-tagged, CVSS-scored, and paired with an Evidence Mode investigation — so you understand the threat, not just the patch number.
Kirki WordPress Plugin SQL Injection via Unsanitized Request Input
WooCommerce Product Feed Manager SQL Injection Flaw
Stored XSS via SVG Upload in ComfyUI /view Endpoint
Path Traversal in ComfyUI Model Preview Functionality
Stored XSS in ComfyUI File Upload Handler
Path Traversal in ComfyUI Image Loading Allows Arbitrary File Access
CodeIgniter Query Builder SQL Injection in deleteBatch()
CodeIgniter Path Traversal in Unsanitized File Uploads
CodeIgniter Upload Validation Bypass Enables Code Execution
Arbitrary PHP Code Execution via Unsafe Widget Definition Storage
WordPress Ultimate Member Plugin Allows Unauthenticated Admin Registration
WordPress FlxWoo Plugin Bypasses Payment Verification
Hard-Coded API Key Enables Unauthenticated DMS+ Device Control
WordPress 2FA Plugin Fails to Validate One-Time Passwords
Unauthenticated PHP Object Injection in Kirki WordPress Plugin
Double-Encoded Payload Bypass Enables Stored XSS in WordPress Admin Plugin
GiveWP Plugin Exposes Donor Information via Unauthenticated API
WordPress Plugin Stores Backups in Publicly Accessible Location
WordPress Real Estate Plugins Allow Unauthenticated Arbitrary File Upload
WordPress Plugin Allows Unauthenticated Email Interception
Unauthenticated File Upload in JS Help Desk Plugin
Geeky Bot Plugin Exposes User Data via Unprotected AJAX
WordPress Plugin Allows Arbitrary File Upload via REST API
Reversible Password Storage Enables Credential Recovery
Unauthenticated Data Access in ANDRITZ HIPASE-250 Configuration
Hard-Coded VNC Credentials in HIPASE Engineering Workstations
Kubernetes Deployment Identity Spoofing in Red Hat ACS
LDAP Filter Injection in 389 Directory Server Replication
Stack Buffer Overflow in 389 Directory Server RUV Parsing
WP Travel Engine Plugin Lacks AJAX Capability Verification
Casky's multi-agent pipeline uses CVE context to generate a structured investigation plan before a single skill runs. Run your first investigation free — no simulation, your actual security work.
Start investigating CVEs free →© 2026 Casky.AI, Inc. · AI Security Investigation