
security-research — Updated!
Vulnerabilidades que reportei à Apache Software Foundation: 46 CVEs em 15 projetos
Atualizações editoriais breves de ferramentas de cibersegurança publicadas.

Vulnerabilidades que reportei à Apache Software Foundation: 46 CVEs em 15 projetos

Security patches for unpatched llama.cpp vulnerabilities (CVE-2026-43626 through CVE-2026-43632) — Cyera Research

Read-only N-able N-central CVE-2026-18556/CVE-2026-18577 post-exploitation IoC hunter for Windows endpoints

PoCs for Wellbia XIGNCODE3 anti-cheat xhunter driver family - xhunter1.sys v2023.12.7.78 and xhunter2.sys v2026.6.1.192 (CVE-2026-15430,…

Decrypts weak encrypted passwords from Argus Surveillance DVR systems via CVE-2022-25012, reconstructing plaintext credentials from DVRParams.ini…

CVE-2026-67620 - Flowise SSRF via incomplete cloud-metadata deny-list (Oracle OCI 192.0.0.192 + Alibaba 100.100.100.200 bypass the DEFAULT_DENY_LIST)

Análise e exploit para CVE-2026-25250, uma bypass do Secure Boot no Horizon DataSys Reboot Restore, onde o shdloader.efi carrega o Shield.efi sem…

Analysis and exploitation of CVE-2025-4275 (Hydr0ph0bia), a Secure Boot trust-chain weakness where firmware variables are used to introduce…

Research on CVE-2025-3052, an Insyde firmware vulnerability that exposes an arbitrary write primitive capable of modifying security-critical pointers.

Scanner offline para CVE-2026-29000 (CVSS 10.0) em org.pac4j:pac4j-jwt. Inspeciona jars/fat-jars diretamente, por isso funciona onde mvn…

A centralized resource for previously documented WDAC bypass techniques

Found a 0-Day in Ghidra: Shared Project File Became a Code Execution Vector