CVE Tracker

CVE Tracker

Vulnerabilities I’m tracking — researching, patching, or mitigating across the homelab. Filter by severity or status, or search by ID, product, or tag.

XZ Utils backdoor (liblzma)

critical
CVE-2024-3094 cvss 10.0 mitigated 2026-03-30

affected: xz-utils 5.6.0 / 5.6.1

Malicious code injected into the xz/liblzma build process creating an SSH backdoor. Audited homelab hosts and confirmed no affected versions deployed.

supply-chainsshbackdoorlinux
reference →

WebP heap buffer overflow (libwebp)

high
CVE-2023-4863 cvss 8.8 watching 2026-02-05

affected: libwebp (Chrome, Electron, many apps)

Heap buffer overflow in libwebp's Huffman decoding, widely exploitable through any app that decodes WebP images. Tracking patch propagation.

browserheap-overflowimage-parsing

Log4Shell (Log4j JNDI RCE)

critical
CVE-2021-44228 cvss 10.0 resolved 2026-01-12

affected: Apache Log4j 2 < 2.17.0

Unauthenticated remote code execution via JNDI lookups in Log4j 2. Reviewing as part of a Java security study; reproduced in an isolated lab VM.

javarcejndilogging