
cve-2026-13934
Structured vulnerability research repo for a Chrome Dawn WebGPU CWE-20 flaw: root cause, patch diff, static verification, severity review, and…

Structured vulnerability research repo for a Chrome Dawn WebGPU CWE-20 flaw: root cause, patch diff, static verification, severity review, and…

Paranoid's library contains implementations of checks for well known weaknesses on cryptographic artifacts.

Technical vulnerability analysis and CVE briefing for CVE-2026-9645 affecting ScadaBR.

This repo contains write ups of vulnerabilities I've found and exploits I've publicly developed.

Select Bugs From Binary Where Pattern Like CVE-1337-Days

TC39 proposal for mitigating prototype pollution

A list of public attacks on BitLocker

Code and data for our paper "Onelogon: Taking over Active Directory Accounts via Netlogon" (WOOT’26).

Log4Shell (CVE-2021-44228) research report — technical breakdown, root cause analysis, and end-to-end lab-reproduced exploit chain with evidence…

Vulnerability research write-ups — CVE-2026-12478 (libsoup), Apple WebKit, Google VRP



Offensive security research hub aggregating original vulnerability advisories, CVE proof-of-concept exploits, conference talks, and internal tooling…

A collection of my public security advisories.

How Enable Security handles security vulnerabilities

MAL-003: Groovy Security Bypass and Stored XSS in Apache OfBiz

MAL-006: XML External Entity in "Try It" in WSO2 ESB