Reg. No. 40203410806VAT LV40203410806

Theme

Book a consultationBook

Cybersecurity backed by verifiable results

These findings were responsibly disclosed, fixed in production software and credited in public vulnerability records.

vulnerabilities in the OffSeq Radar database
100K+
national eID systems hardened
2
public disclosures
10
recognised security researcher
CERT.LV

10

RSS feed

Explore our research and tooling

Results

Newest first · 10 disclosures
SeverityFindingAdvisoryYear
10.0CriticalRemote code execution in the OZOLS ERP via an abandoned update domainOZOLS (OzolsSQL) for WindowsCVE-2026-22306 (opens in a new tab)2026
8.7HighSQL injection in the Zalktis accounting app via e-invoice importsZalktis accounting software (Windows)CVE-2026-59109 (opens in a new tab)2026
5.8MediumAuthorization bypass in 8x8’s JaaS SIP calling gatewayJitsi as a Service (JaaS) — 8x8 SIP gateway2026
7.3HighRemote code execution in Latvia’s national eID signing softwareeParakstītājs 3.0 for Windows (< 1.10.0)CVE-2026-0392 (opens in a new tab)2026
8.0HighCross-instance configuration poisoning in X-RoadX-Road Security Server (< 7.8.2)GHSA-c5gr-pcm6-828r (opens in a new tab)2026
6.5MediumPre-authentication denial of service in X-Road signature verificationX-Road Security Server (< 7.8.2)GHSA-rc33-88jw-c5jp (opens in a new tab)2026
CriticalCommand injection fixed in Estonia’s national eID softwareDigiDoc4 – Estonia’s official eID signing application2026
7.5HighSWQL injection in SolarWinds PlatformSolarWinds Platform (≤ 2024.1 SR 1)CVE-2024-28996 (opens in a new tab)2024
6.1MediumCross-site scripting vulnerability in Oracle Enterprise Command CenterOracle E-Business Suite – ECC FrameworkCVE-2023-22107 (opens in a new tab)2023
HighSQL injection affecting customer data, responsibly disclosedInternational company (responsibly anonymized)2023

Certified to international standards

  • OSCPOffSec
  • Lead Pen Test ProfessionalPECB
  • ISO/IEC 27001 Senior Lead AuditorPECB
  • Certified Information Systems AuditorISACA
  • Red Team OperationsClarified Security
  • Critical Information Infrastructure ProtectionNATO CCDCOE
  • Web Applications Attack & DefenceNATO CCDCOE
  • IT Systems Attack & DefenseCybExer
  • CybercrimeCEPOL
  • Cyber Bite: DarkwebCEPOL
  • OSINT – CryptocurrenciesCEPOL
  • Security Awareness: Privileged AccountsSANS