What we find
Anonymized results from real security assessments across industries. Every finding verified with proof-of-concept reproduction.
Password reset poisoning via X-Forwarded-Host header injection leading to full account takeover
WAF bypass via mobile User-Agent exposed 500M+ user profiles through IDOR with sequential IDs
Trailing slash path normalization bypassed authentication on 30+ endpoints across 10 microservices
Unauthenticated Docker registry exposed 652 repositories with proprietary source code and infrastructure configs
Mock cryptography module enabled in production allowed forging election result signatures
CORS wildcard with credentials on 9+ hosts enabled cross-origin API token theft
Five CloudFront subdomain takeovers via dangling CNAME records under parent domain
Patient record IDOR through sequential appointment IDs exposed PHI across tenant boundaries
These are real results
400+ targets assessed. 1,400+ vulnerabilities reported. 320+ critical-severity findings. All through manual testing — not scan dumps.
How to read these results
Are these findings from real assessments?
Yes. The examples on this page are anonymized patterns from real client assessments and coordinated-disclosure work. Every issue listed here was verified with proof-of-concept reproduction.
What kinds of vulnerabilities does Raijuna usually uncover?
Raijuna frequently finds broken access control, authentication bypasses, API exposure, infrastructure misconfiguration, and multi-step business-logic flaws that automated scanners often miss.
What happens after an assessment starts?
Raijuna scopes the engagement, maps the attack surface, performs manual testing, validates every finding with a PoC, delivers remediation guidance, and retests after fixes are implemented.
Use the scoping wizard after reviewing real results
If these findings look similar to what worries your team, answer a few short questions and get a recommended engagement path before you reach out.
Answer a few short questions and get a suggested engagement path with the right next step.
Need a vertical-specific assessment page?
These results show patterns across many environments. If you want to move into a page tailored to your sector, start from one of the industry assessment paths below.
Open the full industry hubSee where proof fits in the full security buying journey
If these anonymized results helped, the buyer journey hub connects proof pages with comparisons, baseline tools, workspace, scoping, assessment, and retest.
Open buyer journeyOpen comparison hub