Joomla JCE_2.9.15 - Remote Code Execution
NanaZip 6.5 - DoS
flyto_core 2.26.7 - Server-Side Request Forgery
phpSysInfo 3.4.5 - IP Allowlist Bypass
Nmap 7.99 - Extension Header Integer Underflow
Using CVE-2026-43499 to root your Galaxy S24 Ultra(SM-S9280 ,(China / Hong Kong SAR / Taiwan))
CVE-2026-73678 — MindsDB Minds Platform unauthenticated RCE via scratchpad exec (CVSS 10.0). Verified end-to-end with real LLM
CVE-2026-73633(S2-072)概念验证代码
POC | GeoServer Unauthenticated SQL injection to complete RCE
CVE-2026-43499 (GhostLock) rt_mutex stack-UAF privilege escalation research on Honor BVL-AN16 (Magic6 Pro, SM8650, kernel 6.1.128). Includes analysis docs, reverse-engineering scripts, disassembly artifacts, and exploit source with honor-BVL-AN16 target adaptation.
CVE-2026-58231 Detection & Confirmation Script
Full root in kernel domain with selinux permissive
CVE-2026-43499 research port for Galaxy Z Fold4 SM-F936W F936WVLU1AVGA (in progress)
PoC for RefluXFS
KSuRoot 2.2.0 — One-click KernelSU rooting based on CVE-2026-43499. Synced from Root-My-Galaxy v0.2.6 with custom payload (.so) import. Mod by hmascs
This package is not a complete root. It flips SELinux to Permissive and holds reclaim long enough for follow-on work. Host `uid=0` is not achieved here.