Penetration Tester | Security Researcher
| CVE | Target | Severity | CVSS | Type |
|---|---|---|---|---|
| CVE-2026-49869 | kestra-io/kestra | Critical | 10.0 | Unauthenticated RCE |
| CVE-2026-82244 | Budibase/budibase | Critical | 9.4 | RCE via Plugin eval() |
| CVE-2026-50189 | appsmithorg/appsmith | High | 8.9 | RCE via Env Var Injection |
| GHSA-xfvv-ggvq-pchh | appsmithorg/appsmith | High | 8.9 | RCE via Env Injection (CVE pending) |
| CVE-2026-55490 | openwrt/openwrt | Moderate | 6.5 | Pre-Auth DoS |
| CVE-2026-55469 | grokability/snipe-it | Moderate | 6.5 | Path Traversal |
| CVE-2026-32034 | openclaw/openclaw | Medium | 5.6 | Session Hijacking |
| CVE-2026-73082 | activepieces/activepieces | Medium | 5.3 | SSRF |
| CVE-2026-49979 | appsmithorg/appsmith | Moderate | 5.1 | SSRF |
AIDA - AI-Driven Security Assessment
Connect AI assistants to 400+ penetration testing tools through the Model Context Protocol (MCP). AIDA automates reconnaissance, vulnerability scanning, exploitation, and post-exploitation workflows by bridging LLMs with offensive security tooling.
| Project | Description | Tech Stack |
|---|---|---|
| ShadeLoader | Shellcode loader with process hollowing and AV evasion techniques | C++ |
| ShellLoader_Hub | Research repository for shellcode injection methods | Documentation |
| Neo-AI | Terminal-integrated AI assistant for security operations | Python |
Email: Vasco0x4@proton.me
Website: vasco0x4.me




