MARCO PACIARONI · BomboBombone
Cybersecurity researcher specializing in Windows and iOS.
This is the public index: credited vulnerabilities, the write-ups behind them, and tools when they are ready to ship.
- PUBLIC CVEs
- 14
- VENDOR
- XenForo
- FOCUS
- Windows · iOS
.rsrc:credits
CVE credits
CVEWRITE-UPCLASSREFERENCES
CVE-2026-73309 CVE-2026-73309: Empty OAuth2 credentials bypass OAuth2 ADVISORY for CVE-2026-73309 (opens in a new tab) CVE record for CVE-2026-73309 (opens in a new tab)
CVE-2026-73310 CVE-2026-73310: OAuth2 redirect URI mismatch OAuth2 ADVISORY for CVE-2026-73310 (opens in a new tab) CVE record for CVE-2026-73310 (opens in a new tab)
CVE-2026-73311 CVE-2026-73311: OAuth2 authorization code replay OAuth2 ADVISORY for CVE-2026-73311 (opens in a new tab) CVE record for CVE-2026-73311 (opens in a new tab)
CVE-2026-73312 CVE-2026-73312: Refresh token replay after access-token expiry OAuth2 ADVISORY for CVE-2026-73312 (opens in a new tab) CVE record for CVE-2026-73312 (opens in a new tab)
CVE-2026-73313 CVE-2026-73313: Passkey accepted for the wrong account Authentication ADVISORY for CVE-2026-73313 (opens in a new tab) CVE record for CVE-2026-73313 (opens in a new tab)
CVE-2026-73314 CVE-2026-73314: PayPal signature check bypass Payments ADVISORY for CVE-2026-73314 (opens in a new tab) CVE record for CVE-2026-73314 (opens in a new tab)
CVE-2026-73315 CVE-2026-73315: PayPal certificate URL SSRF SSRF ADVISORY for CVE-2026-73315 (opens in a new tab) CVE record for CVE-2026-73315 (opens in a new tab)
CVE-2026-73316 CVE-2026-73316: PayPal webhook replay Payments ADVISORY for CVE-2026-73316 (opens in a new tab) CVE record for CVE-2026-73316 (opens in a new tab)
CVE-2026-73317 CVE-2026-73317: ACP rebuild authorization bypass Authorization ADVISORY for CVE-2026-73317 (opens in a new tab) CVE record for CVE-2026-73317 (opens in a new tab)
CVE-2026-73318 CVE-2026-73318: Missing permission checks on agreement resets Authorization ADVISORY for CVE-2026-73318 (opens in a new tab) CVE record for CVE-2026-73318 (opens in a new tab)
CVE-2026-73319 CVE-2026-73319: JavaScript URI in dynamic redirects XSS ADVISORY for CVE-2026-73319 (opens in a new tab) CVE record for CVE-2026-73319 (opens in a new tab)
CVE-2026-73320 CVE-2026-73320: Unauthenticated unfurl result disclosure Information disclosure ADVISORY for CVE-2026-73320 (opens in a new tab) CVE record for CVE-2026-73320 (opens in a new tab)
.rsrc:interrupts
Security meme interrupts
INT 01 Malware poking with a stick The research workflow, accurately summarized. @vxunderground · OPEN ON X ↗ (opens in a new tab) INT 02 A nuclear missile into the internet When a supply-chain incident lands right before bed. @vxunderground · OPEN ON X ↗ (opens in a new tab) INT 03 Security complaints, illustrated A 2018 cartoon for the recurring “why is security stopping me?” conversation. @JosephSteinberg / @tomfishburne · OPEN ON X ↗ (opens in a new tab)
.rsrc:tools
Tools
00000000 <no public symbols> Nothing released here yet. This slot is reserved for tools and scripts.