cve:start

CVEs

Most CVE writeups just restate the advisory back at you. I'd rather know whether the thing is actually reachable, or whether it's a 9.8 that quietly needs admin creds and local access before it does anything at all.

So that's what these are. One page per bug, what it actually does when you poke at it, and a verdict at the end – Theoretical, Reachable, Exploitable, or Weaponized. I show how I got there so you can tell me I'm wrong.

Everything is published and patched before it goes up here. I'm not posting working exploits. If that's what you came for, sorry.

Sorted by year.