# offensive security · bug bounty · ctf
PNDSEC started as one researcher's bug-bounty handle. It's growing into a small team — web & mobile penetration testing, CTF, and open-source tooling for people who like taking things apart.
| cve | vendor / product | added |
|---|---|---|
| CVE-2026-5430 | WSO2 / Multiple Products | 2026-09-24 |
| CVE-2026-71362 | Adobe / Commerce and Magento | 2026-09-24 |
| CVE-2026-93952 | Arista / VeloCloud Orchestrator | 2026-09-22 |
| CVE-2026-94127 | F5 / BIG-IP APM | 2026-09-22 |
| CVE-2026-93616 | Check Point / Multiple Products | 2026-09-22 |
1723 actively exploited CVEs tracked by CISA — full catalog