Evidence archive
Security Findings & Disclosures
The complete public record behind the portfolio: assigned CVEs, platform-masked disclosures (FVE), and per-project ledgers in a form that is searchable and linkable.
Disclosure summary
Memory corruption · 9
Kernel and parser heap/buffer overflow paths
Out-of-bounds read · 2
Packet and protocol-parser bounds failures
Injection / command execution · 5
Command and argument injection paths
Authentication / access control · 4
Authentication bypass and access-control flaws
Logic / denial of service · 8
Validation or abort paths with availability impact
Unclassified · 1
Items whose upstream CWE is unknown
CVE record, advisory, and public finding are different labels
A CVE is the public vulnerability record. A vendor may separately publish an advisory, and some findings are documented only in a patch or issue without a CVE. This ledger counts 24 assigned records as CVE disclosures and keeps 4 platform-masked disclosures (FVE) separate. Severity is never inferred from an identifier.
2026
Database
1 CVEs
- CVE-UNASSIGNED-MDEV-40571Logic / denial of service
MariaDB .frm parsing OOB read leads to vtable hijacking RCE
Impact: CVSS 8 (high)
2026
LLM
3 CVEs
- CVE-2026-52130Logic / denial of service
llama.cpp json-schema-to-grammar uncontrolled recursion
Impact: CVSS 7.5 (high)
- CVE-2026-52131Logic / denial of service
llama.cpp gguf_reader::read reachable assertion
Impact: CVSS 5.5 (medium)
- CVE-2026-52132Logic / denial of service
llama.cpp /rerank negative top_n denial of service
Impact: CVSS 7.5 (high)
2026
Web
4 CVEs
- FVE-2026-8617-75112Authentication / access control
Masked web disclosure from Findthegap bug bounty platform
Impact: CVSS 7.5 (high)
- FVE-2026-8617-74526Authentication / access control
Masked web disclosure from Findthegap bug bounty platform
Impact: CVSS 7.5 (high)
- FVE-2026-8617-74507Authentication / access control
Masked web disclosure from Findthegap bug bounty platform
Impact: CVSS 9.8 (critical)
- FVE-2026-8617-74513Unclassified
Masked web disclosure from Findthegap bug bounty platform
Impact: CVSS 7.5 (high)
2024
IoT
5 CVEs
- CVE-2024-33788Injection / command execution
Linksys E5600 command injection
Impact: CVSS 8 (high)
- CVE-2024-33789Injection / command execution
Linksys E5600 command injection
Impact: CVSS 8.2 (medium)
- CVE-2024-33791Injection / command execution
netis-systems MEX605 cross-site scripting
Impact: CVSS 4.6 (high)
- CVE-2024-33792Injection / command execution
netis-systems MEX605 OS command execution
Impact: CVSS 9.8 (critical)
- CVE-2024-33793Injection / command execution
netis-systems MEX605 OS command execution
Impact: CVSS 5.3 (medium)
2019
Kernel
BoB team project16 CVEs
- CVE-2019-19927Out-of-bounds read
Linux kernel ttm slab out-of-bounds read
Impact: CVSS 6 (medium)
- CVE-2019-19813Memory corruption
Linux kernel btrfs use-after-free
Impact: CVSS 5.5 (medium)
- CVE-2019-19814Memory corruption
Linux kernel f2fs slab out-of-bounds write
Impact: CVSS 7.8 (high)
- CVE-2019-19815Logic / denial of service
Linux kernel f2fs NULL pointer dereference
Impact: CVSS 5.5 (medium)
- CVE-2019-19816Memory corruption
Linux kernel btrfs slab out-of-bounds write
Impact: CVSS 7.8 (high)
- CVE-2019-19447Memory corruption
Linux kernel ext4 use-after-free
Impact: CVSS 7.8 (high)
- CVE-2019-19448Memory corruption
Linux kernel btrfs use-after-free
Impact: CVSS 7.8 (high)
- CVE-2019-19449Out-of-bounds read
Linux kernel f2fs slab out-of-bounds read
Impact: CVSS 7.8 (high)
- CVE-2019-19377Memory corruption
Linux kernel btrfs use-after-free
Impact: CVSS 7.8 (high)
- CVE-2019-19378Memory corruption
Linux kernel btrfs slab out-of-bounds write
Impact: CVSS 7.8 (high)
- CVE-2019-19318Memory corruption
Linux kernel btrfs use-after-free
Impact: CVSS 4.4 (medium)
- CVE-2019-19319Memory corruption
Linux kernel ext4 slab out-of-bounds write
Impact: CVSS 6.5 (medium)
- CVE-2019-19036Logic / denial of service
Linux kernel btrfs root node NULL pointer dereference
Impact: CVSS 5.5 (medium)
- CVE-2019-19037Logic / denial of service
Linux kernel ext4 NULL pointer dereference
Impact: CVSS 5.5 (medium)
- CVE-2019-19039Authentication / access control
Linux kernel btrfs information disclosure
Impact: CVSS 5.5 (medium)
- CVE-2019-18885Logic / denial of service
Linux kernel btrfs NULL pointer dereference
Impact: CVSS 5.5 (high)