How an out-of-bounds read in MariaDB's .frm metadata parser can be turned into a forged C++ object with a fake vtable, reaching arbitrary code execution as the mariadbd process (MDEV-40571).
Exploiting HackSys Extreme Vulnerable Driver (HEVD) on Windows 7 x86: a kernel stack buffer overflow using token-stealing shellcode, and privilege escalation via a Write-What-Where overwrite of the HalDispatchTable
Analysis of an Integer Overflow (SMBGhost) and an uninitialized kernel memory leak (SMBleed) in the SMBv3.1.1 decompression routine, and a Pre-Auth RCE achieved by chaining the two bugs