Too Many Attempts

Please wait before trying again

30
Takedowns ↗
Cyber Intelligence Platform

See what
others can't.

AI-assisted vulnerability scanning, attack surface discovery, and CVE monitoring for teams that need clear, repeatable security checks.

Vulnerabilities reported to
Works natively with
Accepted into
NVIDIA
Inception Program
Zendesk
for Startups
Products

One team. Two ways
we keep you safe.

Capabilities

Built for the threats that haven't happened yet.

001

Threat Cartography

Continuous mapping of your attack surface across every layer — from exposed APIs to shadow infrastructure nobody told you about.

002

Risk Prioritisation

Correlates scan findings with CVE intelligence and severity data so teams can focus on the exposures most likely to matter.

003

Automated Validation

Runs repeatable security checks and rescans to help confirm findings and verify whether remediation changed the exposed attack surface.

004

Protocol & Configuration Checks

Reviews exposed services, TLS configuration, DNS, headers, and detected technologies for common weaknesses and outdated components.

Real-Time Intelligence

The network never sleeps.

0
NVD Sync Interval
0
Scans Executed Daily
0
CVEs in Coverage Database
0
Threat Intel Feeds Integrated

Data from NIST NVD, Vulners and Tavily search.

Latest Research

Fresh from our research desk.

Recent vulnerability analysis and defensive notes from the Vesamuni research desk.

Latest research is loading.

Ready to see
everything?

Join the organisations that refuse to be reactive. Get early access to the Vesamuni intelligence platform.

Documentation

Platform Documentation

Overview

Vesamuni is an early-stage cyber security platform that brings vulnerability scanning, CVE intelligence, attack surface discovery, and security reporting into a single dashboard.

Account access uses server-side sessions, Argon2 password hashing, CSRF protection, secure cookies, and optional authenticator-based two-factor authentication.

Getting Started

Vesamuni is currently in early access. Approved clients receive an account from the team.

Step 1
Receive and accept your client invitation.

Step 2
Sign in and add the public URL you want to monitor.

Step 3
Enable two-factor authentication from the security dashboard.

Step 4
Contact the team to confirm scan scope during early access.

Authentication

The current client dashboard uses secure server-side sessions. Public API credentials are not generally available during early access.

API Reference

A public scanning API is planned but not yet released. Current HTTP endpoints support the website, account management, billing, and internal administration.

Integrations

Stripe billing is available now. Additional workflow integrations and public SDKs are roadmap items and will be documented only when released.

About

We build what defenders need.

Vesamuni was founded with a singular conviction: the asymmetry between attackers and defenders is a design problem, not an inevitability.

What we build

Takedowns finds leaked and non-consensual content across Google, Reddit, Telegram and file hosts, and files the removal notices as the owner's agent, so creators and survivors never have to put their own name on them. More than 380,000 pirate links have been removed so far.

The Vesamuni Platform brings vulnerability scanning, CVE intelligence and attack surface discovery into one dashboard for teams that need clear, repeatable security checks.

Our research desk publishes analysis of new CVEs every day, and the team has found and reported vulnerabilities through the bug bounty programs of companies including Xiaomi, Polygon, Anduril and KOHO.

Our Philosophy

We don't believe in security theatre. Every feature should help teams discover, understand, or remediate a real exposure. Vesamuni is being built iteratively with feedback from security-minded operators and developers.

Melbourne & Colombo

We work from Melbourne, Australia and Colombo, Sri Lanka: one close to Australia's security market, one in South Asia's fast-growing tech scene.

The Name

Vesamuni (වෙසමුනි) — In Sri Lankan folklore, Vesamuni is the fearsome king of demons. He rules the Yakkas with an iron fist, commanding spirits that once spread chaos across the land. Yet he chose to protect rather than destroy — forbidding his demons from killing, transforming them into instruments of order.

Armed with a magical golden sword that flies from his hand to strike down enemies before they see it coming, Vesamuni embodies power turned to protection.

We do the same. The tools of attackers, wielded by defenders.

Careers

Join us.

We're a small team building something meaningful. If you're passionate about security and want to make an impact, we'd love to hear from you.

founders@vesamuni.com

Melbourne, Australia · Colombo, Sri Lanka · Remote

Research

Coming soon.

We're working on publishing our security research. Follow us to get notified when we release new findings.

research@vesamuni.com
08/10/2026 / CVE, CWE-522, Security Research

CVE-2026-101331: IBM Langflow OSS 1.0.0 through 1.12.2 could allow a remote authenticated attacker to obtain sensitive information due…

CVE-2026-101331: IBM Langflow OSS 1.0.0 through 1.12.2 could allow a r

CVE-2026-101331 analysis covering impact, affected products, versions, remediation, and cross-checked defender guidance.

CVE-2026-101331 is a vulnerability published by NVD on 10/7/2026.

What happened

IBM Langflow OSS 1.0.0 through 1.12.2 could allow a remote authenticated attacker to obtain sensitive information due to insufficiently protected credentials.

Affected products and versions

  • langflow langflow unspecified version (from 1.0.0 before 1.12.3)

Severity and weakness

CVSS: HIGH 7.7. Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N.

Weaknesses: CWE-522.

Known exploitation

No CISA KEV entry is currently attached to the NVD record.

What defenders should do

  1. Identify whether the affected product and version range exists in production.
  2. Review vendor advisories and release notes before change windows.
  3. Patch, upgrade, disable the vulnerable component, or apply vendor mitigations.
  4. Verify the running version after deployment, not only the package inventory.

Official and supporting references

Source record

CVECWE-522Security Research
Contact

Let's talk.

Whether you're evaluating the platform, exploring a partnership, or have a security research inquiry, we'd love to hear from you.

hello@vesamuni.com
Melbourne, VIC, Australia
Colombo, Sri Lanka
Response within 24 hours
Required.
Valid email required.
Required.
System Status

Operational Status

Website and client dashboard online

Checked when this page loaded. For anything urgent, email hello@vesamuni.com.

WebsiteOnline
Client sign-in & dashboardOnline
CVE research feed no posts yet Delayed
Takedowns separate servicetakedowns.vesamuni.com ↗
AI Guided Pentesting Platform

AI Guided Pentesting
that never stops.

Continuous security testing priced by protected asset, not by scan. Run unlimited rescans, monitor new CVEs, and use monthly AI pentest credits for deeper validation.

Monthly subscriptions. Cancel or change plan from the billing portal.

Network Security
Scout
$79/mo
per month

Network vulnerability assessment, attack surface discovery, cloud checks, and continuous CVE monitoring for small security teams.

Scanning & Testing
  • 5 protected assets with unlimited scans and rescans during each monthly cycle
  • 1 AI pentest scan / month — AI-guided penetration test targeting your highest-risk external asset
  • Full NVD database access — real-time CVE matching against your installed plugins, themes & core version
  • OWASP Top 10 coverage with severity scoring (Critical → Info)
Intelligence & Monitoring
  • NVD-backed plugin & theme vulnerability detection
  • WordPress core version security tracking
  • SSL/TLS certificate monitoring
  • Outdated software & end-of-life component alerts
Reporting
  • Basic reports — scan summary with findings, severity, and remediation steps
  • PDF export of scan results
  • Dashboard access — single-site view
Support
  • Email support
  • Vesamuni knowledge base access
Full-cycle Pentesting
Vanguard
$249/mo
per month

Deep vulnerability testing and reporting with the highest self-service AI pentest allowance, continuous asset monitoring, and configurable exports.

Scanning & Testing
  • 5 protected assets with unlimited vulnerability scans and rescans
  • 10 AI pentest scans / month — deep AI-guided penetration testing with multi-vector attack simulation
  • Real-time NVD/CVE alerts — instant notification when new vulnerabilities affect your environment
  • Full web application, API & infrastructure scanning
  • AI-driven false positive elimination with proof-of-exploit validation
  • On-demand re-scans after remediation (unlimited)
Intelligence & Monitoring
  • Continuous dashboard visibility into monitored assets and findings
  • Continuous attack surface discovery & asset enumeration
  • Threat intelligence feed — CVE tracking + emerging threat advisories
  • Technology stack fingerprinting & change detection
  • SSL/TLS, DNS, domain & certificate transparency monitoring
Reporting & API
  • Custom reports — configurable report templates with branding, scope & audience controls
  • API access — REST API for scan orchestration, results & webhooks, included when it launches Planned
  • Priority remediation guidance — risk-ranked action items with context & fix recommendations
  • Compliance alignment mapping (ISO 27001, SOC 2, PCI-DSS indicators) Planned
  • Risk trend dashboards with historical comparison
  • PDF, CSV & JSON export
Support
  • Priority email + chat support
  • Dedicated onboarding & configuration assistance
  • Vesamuni Threat Advisory bulletins
  • Early access to new platform features
Custom Platform Plan
Enterprise
Custom
tailored to your environment

A custom software plan for larger asset inventories, additional testing capacity, tailored scan schedules, and product onboarding. Scope and limits are agreed before activation.

Scanning & Testing
  • Custom protected asset allowance based on your scope
  • Unlimited automated rescans across included assets
  • Custom monthly AI pentest credit allowance
  • Web application, API, infrastructure, WordPress, SSL/TLS, and cloud checks
  • Configurable scheduled scans and finding notifications
  • AI-assisted finding review and remediation guidance
  • Custom scan profiles for industry-specific threat models
Monitoring & Workflow
  • Continuous attack surface discovery and risk scoring
  • Email alerts for new critical and high-severity findings
  • Scan history and risk trend comparison
  • Webhook-based workflow integration Planned
Reporting & API
  • Custom reports with configurable templates and structured output
  • Full REST API access Planned
  • Compliance control mapping indicators for supported frameworks Planned
  • Executive risk summaries and historical trend reporting
  • PDF, CSV, and JSON exports
Product Support
  • Priority email support during published business hours
  • Remote onboarding and configuration assistance
  • Product feedback and roadmap sessions
  • Early access to all new Vesamuni modules & features
At a glance

Side-by-side comparison
across all tiers.

Scout Sentinel Vanguard Enterprise
Price $79/mo $249/mo Custom
Protected Assets 5 assets 5 assets Unlimited
Scans & Rescans Unlimited Unlimited Unlimited
AI Pentest Scans / mo 1 10 Unlimited
NVD Database Access ✓ ✓ ✓
NVD/CVE Monitoring — Real-time Real-time
Reports Basic Custom Custom + Board-ready
Email Alerts — Real-time Real-time
API Access — Planned Planned
Remediation Guidance Basic Priority + Context Priority + Context
Attack Surface Discovery — Continuous Full ASM
Web App Scanning WordPress Full stack Full stack + API + Cloud
Compliance Mapping — Planned Planned
Custom Report Templates — ✓ ✓
Pricing Notes
Transparent Monthly Billing

Pay month to month in USD. Change or cancel through Stripe's secure billing portal.

Asset-based Allowances

Plans limit unique protected assets, not scans. Rescan covered assets as often as needed.

Researchers & Non-profits

Introductory rates for independent security researchers, academic institutions, and registered non-profits. Reach out and mention your organisation type.

Upgrades

Start on any tier and upgrade at any time. Your scan history, configurations, and discovered assets carry over seamlessly.

Enterprise

Custom software plan for larger asset allowances, additional testing credits, tailored scan schedules, onboarding, and priority product support.

Ready to see
everything?

Not sure which plan fits? Tell us what you need to protect and we will recommend one, or scope a custom plan.

Protected Workspace

Security Dashboard

Monitor your subscription, protected perimeter, and account security.

Plan Checking... Loading billing status
Protected Assets 0 / 0 No perimeter configured
Account Security Checking... Reviewing controls
Subscription Renewal Not scheduled Managed securely by Stripe
Protected Perimeter

Primary monitored asset

Pending setup

HTTPS is recommended. Private network and local addresses are rejected.

Credentials

Change password

At least 12 characters Passwords match Different from current password

Changing your password invalidates every other active session.

🐸