Independent engineer · Suphan Buri, Thailand

Full-stack · Mobile · Application security

I build useful software.
I find what breaks it.

Product engineer and security researcher shipping mobile, web, and native desktop software — with 15 published CVE records, including a Microsoft .NET SDK privilege escalation, and private research spanning WordPress, NoMachine, Foxit PDF, and additional software.

15
Published CVE records
Private
Unpublished research active
5
Live products
Research signal Live

01 / Security research

Disclosure archive,
ordered by impact.

Published records are sorted by CVSS base score, then by reach when scores match — vendor platforms and WordPress plugins in one archive. Private research remains separate until details can be disclosed.

3 Critical CVSS 9.0–10.0
6 High CVSS 7.0–8.9
6 Medium CVSS 4.0–6.9
Private queue · NoMachine · Foxit PDF · additional findings

Featured disclosure · Microsoft

.NET SDK elevation of privilege
to SYSTEM on Windows.

The dotnet workload command in the .NET SDK exposes a named pipe with a weak ACL. Any local user can drive that pipe to create or truncate arbitrary files in the context of another local user — including a privileged one — turning a low-privilege foothold into full SYSTEM control. Fixed in the June 2026 servicing release across every supported .NET SDK line.

CVE-2026-45490
7.8 High severity Elevation of privilege
Vendor
Microsoft
Affected
.NET SDK 8.0, 9.0, 10.0 — Windows only
Weakness
CWE-285 improper authorization
Vector
AV:L / AC:L / PR:L / UI:N / C:H / I:H / A:H
Disclosed
9 June 2026 · Patch Tuesday
Reported by
kai63001

Showing all 15 published records

  1. 01 9.8 critical CVE-2026-7458 User Verification Authentication bypass WordPress reach 5K+ active installs
  2. 02 9.3 critical CVE-2026-57739 AcyMailing SMTP Newsletter Blind SQL injection WordPress reach 7K+ active installs
  3. 03 9.3 critical CVE-2026-42747 Easy Form Builder Blind SQL injection WordPress reach 1K+ active installs
  4. 04 8.8 high CVE-2026-7465 Spectra Gutenberg Blocks Remote code execution WordPress reach 1M+ active installs
  5. 05 8.5 high CVE-2026-48874 GamiPress SQL injection WordPress reach 10K+ active installs
  6. 06 8.1 high CVE-2026-3453 ProfilePress Subscription IDOR WordPress reach 100K+ active installs
  7. 07 8.1 high CVE-2026-3629 Import and export users Privilege escalation WordPress reach 70K+ active installs
  8. 09 7.5 high CVE-2026-49112 Shared Files Path traversal WordPress reach 4K+ active installs
  9. 10 6.5 medium CVE-2026-3454 GenerateBlocks Sensitive data exposure WordPress reach 200K+ active installs
  10. 11 6.5 medium CVE-2026-48965 XCloner Sensitive data exposure WordPress reach 10K+ active installs
  11. 12 6.4 medium CVE-2026-3722 Auto Image Attributes Stored cross-site scripting WordPress reach 100K+ active installs
  12. 13 6.4 medium CVE-2026-3361 WP Store Locator Stored cross-site scripting WordPress reach 50K+ active installs
  13. 14 5.4 medium CVE-2026-3369 Better Find and Replace Stored cross-site scripting WordPress reach 40K+ active installs
  14. 15 5.3 medium CVE-2026-4664 Customer Reviews for WooCommerce Authentication bypass WordPress reach 80K+ active installs

Unpublished / coordinated

Private research in progress.

Details limited until public
Private research
NoMachine Unpublished security work

The affected component and technical details are intentionally withheld while the disclosure remains private.

Details withheld
Private research
Foxit PDF Unpublished security work

The affected component and technical details are intentionally withheld while the disclosure remains private.

Details withheld
Private queue
Additional findings More research is not public yet

Additional vendor and vulnerability details will be added only when they can be disclosed responsibly.

Details withheld

Unpublished work is excluded from severity rankings, reach claims, and technical summaries until disclosure is appropriate.

03 / How I work

One engineer.
The whole system.

I move comfortably from product decisions to low-level implementation — and I keep security in the room before launch.

01

Product engineering

Interfaces, APIs, data models, and production delivery treated as one product system.

02

Mobile products

Native iOS and cross-platform Flutter apps shaped for the realities of app-store distribution.

03

Security research

Authentication, authorization, business logic, API security, data exposure, and responsible disclosure.

Working stack

RustSwiftFlutterTypeScriptNext.jsSvelteNode.jsGoPostgreSQLMongoDBDockerGoogle Cloud

04 / Start a conversation

Available for focused product and security work

Have something worth
building or breaking?

A product to ship, a security question to investigate, or a disclosure to coordinate — send a clear signal.