# offensive security · bug bounty · ctf
PNDSEC started as one researcher's bug-bounty handle. It's growing into a small team — web & mobile penetration testing, CTF, and open-source tooling for people who like taking things apart.
| cve | vendor / product | added |
|---|---|---|
| CVE-2026-59822 | BerriAI / LiteLLM | 2026-09-02 |
| CVE-2026-48710 | Kludex / Starlette | 2026-09-02 |
| CVE-2026-49869 | Kestra / Kestra OSS | 2026-09-02 |
| CVE-2026-82329 | JFrog / Artifactory | 2026-09-02 |
| CVE-2026-9586 | Sangoma / Switchvox | 2026-09-02 |
1694 actively exploited CVEs tracked by CISA — full catalog