CVE Tracker
CVE Tracker
Vulnerabilities I’m tracking — researching, patching, or mitigating across the homelab. Filter by severity or status, or search by ID, product, or tag.
XZ Utils backdoor (liblzma)
criticalaffected: xz-utils 5.6.0 / 5.6.1
Malicious code injected into the xz/liblzma build process creating an SSH backdoor. Audited homelab hosts and confirmed no affected versions deployed.
reference →WebP heap buffer overflow (libwebp)
highaffected: libwebp (Chrome, Electron, many apps)
Heap buffer overflow in libwebp's Huffman decoding, widely exploitable through any app that decodes WebP images. Tracking patch propagation.
Log4Shell (Log4j JNDI RCE)
criticalaffected: Apache Log4j 2 < 2.17.0
Unauthenticated remote code execution via JNDI lookups in Log4j 2. Reviewing as part of a Java security study; reproduced in an isolated lab VM.