Skip to content

Evidence archive

Security Findings & Disclosures

The complete public record behind the portfolio: assigned CVEs, platform-masked disclosures (FVE), and per-project ledgers in a form that is searchable and linkable.

Disclosure summary

24published CVEs
4masked disclosures (FVE)
1awaiting ID
5research groups

Memory corruption · 9

Kernel and parser heap/buffer overflow paths

Out-of-bounds read · 2

Packet and protocol-parser bounds failures

Injection / command execution · 5

Command and argument injection paths

Authentication / access control · 4

Authentication bypass and access-control flaws

Logic / denial of service · 8

Validation or abort paths with availability impact

Unclassified · 1

Items whose upstream CWE is unknown

CVE record, advisory, and public finding are different labels

A CVE is the public vulnerability record. A vendor may separately publish an advisory, and some findings are documented only in a patch or issue without a CVE. This ledger counts 24 assigned records as CVE disclosures and keeps 4 platform-masked disclosures (FVE) separate. Severity is never inferred from an identifier.

2026

Database

1 CVEs

  • CVE-UNASSIGNED-MDEV-40571Logic / denial of service

    MariaDB .frm parsing OOB read leads to vtable hijacking RCE

    Impact: CVSS 8 (high)

2026

LLM

3 CVEs

  • CVE-2026-52130Logic / denial of service

    llama.cpp json-schema-to-grammar uncontrolled recursion

    Impact: CVSS 7.5 (high)

  • CVE-2026-52131Logic / denial of service

    llama.cpp gguf_reader::read reachable assertion

    Impact: CVSS 5.5 (medium)

  • CVE-2026-52132Logic / denial of service

    llama.cpp /rerank negative top_n denial of service

    Impact: CVSS 7.5 (high)

2026

Web

4 CVEs

  • FVE-2026-8617-75112Authentication / access control

    Masked web disclosure from Findthegap bug bounty platform

    Impact: CVSS 7.5 (high)

  • FVE-2026-8617-74526Authentication / access control

    Masked web disclosure from Findthegap bug bounty platform

    Impact: CVSS 7.5 (high)

  • FVE-2026-8617-74507Authentication / access control

    Masked web disclosure from Findthegap bug bounty platform

    Impact: CVSS 9.8 (critical)

  • Masked web disclosure from Findthegap bug bounty platform

    Impact: CVSS 7.5 (high)

2024

IoT

5 CVEs

  • CVE-2024-33788Injection / command execution

    Linksys E5600 command injection

    Impact: CVSS 8 (high)

  • CVE-2024-33789Injection / command execution

    Linksys E5600 command injection

    Impact: CVSS 8.2 (medium)

  • CVE-2024-33791Injection / command execution

    netis-systems MEX605 cross-site scripting

    Impact: CVSS 4.6 (high)

  • CVE-2024-33792Injection / command execution

    netis-systems MEX605 OS command execution

    Impact: CVSS 9.8 (critical)

  • CVE-2024-33793Injection / command execution

    netis-systems MEX605 OS command execution

    Impact: CVSS 5.3 (medium)

2019

Kernel

BoB team project

16 CVEs

  • CVE-2019-19927Out-of-bounds read

    Linux kernel ttm slab out-of-bounds read

    Impact: CVSS 6 (medium)

  • CVE-2019-19813Memory corruption

    Linux kernel btrfs use-after-free

    Impact: CVSS 5.5 (medium)

  • CVE-2019-19814Memory corruption

    Linux kernel f2fs slab out-of-bounds write

    Impact: CVSS 7.8 (high)

  • CVE-2019-19815Logic / denial of service

    Linux kernel f2fs NULL pointer dereference

    Impact: CVSS 5.5 (medium)

  • CVE-2019-19816Memory corruption

    Linux kernel btrfs slab out-of-bounds write

    Impact: CVSS 7.8 (high)

  • CVE-2019-19447Memory corruption

    Linux kernel ext4 use-after-free

    Impact: CVSS 7.8 (high)

  • CVE-2019-19448Memory corruption

    Linux kernel btrfs use-after-free

    Impact: CVSS 7.8 (high)

  • CVE-2019-19449Out-of-bounds read

    Linux kernel f2fs slab out-of-bounds read

    Impact: CVSS 7.8 (high)

  • CVE-2019-19377Memory corruption

    Linux kernel btrfs use-after-free

    Impact: CVSS 7.8 (high)

  • CVE-2019-19378Memory corruption

    Linux kernel btrfs slab out-of-bounds write

    Impact: CVSS 7.8 (high)

  • CVE-2019-19318Memory corruption

    Linux kernel btrfs use-after-free

    Impact: CVSS 4.4 (medium)

  • CVE-2019-19319Memory corruption

    Linux kernel ext4 slab out-of-bounds write

    Impact: CVSS 6.5 (medium)

  • CVE-2019-19036Logic / denial of service

    Linux kernel btrfs root node NULL pointer dereference

    Impact: CVSS 5.5 (medium)

  • CVE-2019-19037Logic / denial of service

    Linux kernel ext4 NULL pointer dereference

    Impact: CVSS 5.5 (medium)

  • CVE-2019-19039Authentication / access control

    Linux kernel btrfs information disclosure

    Impact: CVSS 5.5 (medium)

  • CVE-2019-18885Logic / denial of service

    Linux kernel btrfs NULL pointer dereference

    Impact: CVSS 5.5 (high)