Below are listed all the CVEs I have discovered and reported.

HIGH
7.5
CVSS
3.1
CVE-2026-30996 PATH TRANSVERSAL
SoftSul SAC-NFe through 2.0.02 - Unauthenticated Path Traversal (Arbitrary File Read) · February 12, 2026

An issue in the file handling logic of the component download.php of SAC-NFe v2.0.02 allows attackers to execute a directory traversal and read arbitrary files from the system via a crafted GET request.

HIGH
8.6
CVSS
3.1
CVE-2026-30995 SQL INJECTION
Slah Informática CMS - All Versions Through 1.5.0 (SQL injection) · February 10, 2026

Slah CMS v1.5.0 and below was discovered to contain a SQL injection vulnerability via the id parameter in the vereador_ver.php endpoint.

HIGH
7.5
CVSS
3.1
CVE-2026-30994 IMPROPER ACCESS CONTROL
Slah Informática CMS - All Versions Through 1.5.0 (Sensitive Data Exposure) · February 03, 2026

Incorrect access control in the config.php component of Slah v1.5.0 and below allows unauthenticated attackers to access sensitive information, including active session credentials.

Note: certain CVEs are still in the verification process due to MITRE's response time or the vendor's 90-day responsible disclosure period.

This list is constantly updated.