How an out-of-bounds read in MariaDB's .frm metadata parser can be turned into a forged C++ object with a fake vtable, reaching arbitrary code execution as the mariadbd process (MDEV-40571).
A command injection vulnerability found in the WPS PIN handling of the E5600 router — authenticated remote code execution via a crafted WPS PIN parameter
Analysis of an Integer Overflow (SMBGhost) and an uninitialized kernel memory leak (SMBleed) in the SMBv3.1.1 decompression routine, and a Pre-Auth RCE achieved by chaining the two bugs