Reproducible lab for CVE-2026-10053 (GitLab npm package-registry path traversal -> arbitrary file write as git). Vulnerable 19.2.1 vs patched 19.2.2, deterministic oracle.
IDOR + Stored XSS via Broken Object-Level Authorization in JoomGallery
Original research and non-destructive PoC for a pre-auth stack buffer overflow via unbounded sscanf scanset in the Netis NC63 ipFilterList handler
Original research and non-destructive PoC for a pre-auth Base64-decoded password stack buffer overflow in Netis NC63 login.cgi
Oracle OID LDAP Server Privileges Management Exploit
4gaBoards < 3.3.9 - User Information Disclosure
GhostLock CVE-2026-43499 research for Galaxy S26 (SM-S942U1/m1q): SELinux Permissive achieved, KASLR + tracefs port, uid=0 boundary documented
GhostLock (CVE-2026-43499) adaptation for non-Android Linux 6.x ARM64
尝试移植CVE-2026-43499提权漏洞到HW P20Pro上
Proof of Concept for CVE-2026-19598 affecting Pods <= 3.3.9.
CVE-2026-18504, CVE-2026-16732 - Draft or TODO
CVE-2026-43499 (GhostLock) — Linux kernel futex PI rt_mutex UAF ARM32 privilege escalation research targeting Huawei Watch 4 Pro (kernel 5.4.210)
CVE-2026-14669 - PostgreSQL to_char() timezone abbreviation heap buffer overflow PoC; for authorized security testing
Windows Defender 0day vulnerability CVE-2026-69414 ShieldBreak
CVE-2026-65400 - Draft or TODO
CVE-2026-15826, CVE-2026-15748
CVE-2026-43499 port for Samsung Galaxy A17