Md Minaruzzaman Shovon

Exploring water systems, modeling, and environmental analysis.

I'm Md Minaruzzaman Shovon, a water resources engineering undergraduate at CUET working across hydrology, hydraulics, GIS, environmental analysis, and applied computational tools, with a focus on river systems, rainfall, air quality, spatial analysis, and practical modeling supported by software.

I use software to make complex water, environmental, and engineering systems easier to analyze, understand, and communicate.

Based in Chattogram, studying and building in water systems.

Current interests include hydrological modeling, remote sensing, environmental monitoring, and research-led engineering tools for decision-making.

Education

Chittagong University of Engineering and Technology (CUET)Undergraduate, Water Resources Engineering
Chittagong CollegeCollege
Chattogram Cantonment Public CollegeSchool

Research & Publications

Research is a central part of this work, especially around hydrology, environmental monitoring, rainfall analysis, and applied machine learning for water-related systems.

Security Advisories & Disclosures

Responsible vulnerability disclosures, CVE advisories, and official vendor changelog credits.

CVE-2026-15048 — GeekyBot Unauthenticated Sensitive Information Exposure

Jul 2026

Discovered and reported CVE-2026-15048, a medium-severity (CVSS 5.3) Information Exposure vulnerability in GeekyBot < 1.2.8. Missing authorization checks allow unauthenticated attackers to retrieve chat-history session metadata, user IDs, and WordPress usernames. Patched in version 1.2.8.

WPScan / CVESecurity Research

CVE-2026-14322 — Timetics Unauthenticated Booking Auto-Approval

Jul 2026

Discovered and reported CVE-2026-14322, a medium-severity (CVSS 5.3) Broken Access Control vulnerability in Timetics < 1.0.57. Unauthenticated users can create fully-approved bookings for priced appointments without making any payment by manipulating payment_method. Patched in version 1.0.57.

WPScan / CVESecurity Research

CVE-2026-10749 — Post Duplicator PHP Object Injection

Jun 2026

Discovered and reported CVE-2026-10749, a high-severity (CVSS 7.2) PHP Object Injection vulnerability in Post Duplicator ≤ 3.0.14. Authenticated Contributors can inject malicious serialized objects via the customMetaData parameter, enabling remote code execution when a gadget chain is present. Patched in version 3.0.15.

WPScan / CVESecurity Research

CVE-2026-57661 — WPComplete Broken Access Control

Jun 2026

Discovered and reported CVE-2026-57661, a medium-severity (CVSS 5.4) Broken Access Control vulnerability in WPComplete ≤ 2.9.5.5. Missing authorization and nonce validation allows Subscriber-level users to perform privileged actions. Patched in version 2.9.5.6.

Patchstack / CVESecurity Research

CVE-2026-14821 — Quiz and Survey Master Missing Authorization

May 2026

Discovered and reported CVE-2026-14821, a low-severity (CVSS 2.7) Missing Authorization vulnerability in Quiz and Survey Master (QSM) < 11.1.5. Authenticated Contributors can delete arbitrary output templates due to missing capability checks. Patched in version 11.1.5.

WPScan / CVESecurity Research

MapPress Maps 2.97.2 Security Assistance

2026

Discovered and reported security vulnerabilities in MapPress Maps for WordPress. Received formal author appreciation and changelog recognition in version 2.97.2 ('Thanks to https://shovon.bd for security assistance in 2.97').

WordPress.orgSecurity Research

WP Store Locator 2.3.1 Security Fix

2026

Discovered and reported a high-severity Stored XSS vulnerability (CVSS 8.1) in WP Store Locator (<= 2.3.0). Coordinated a responsible disclosure resulting in a critical patch in version 2.3.1 and formal recognition in the changelog.

WordPress.orgSecurity Research

Tools & Methods

Methods, software, and technical tools I use across hydrology, GIS, analysis, and engineering workflows.

GIS/ML Modelling

QGISArcGISETABSAutoCADHEC-RAS

Programming & ML

PythonNumPyMATLABPyTorchTensorFlowMachine LearningCNNANNLLM Fine-tuning

Certifications

CISSP by InfoSecInfoSEC, Jun 2025
Cybersecurity Attack and Defense FundamentalsEC-Council, Jun 2025
Microsoft Python DevelopmentMicrosoft, Jun 2025
Google Cybersecurity ProfessionalGoogle, Jun 2025
GIS & Its ApplicationEnhancing Digital Government & Economy Project, Apr 2025

Achievements

Ranked 11th - NextGen Hackathon

International Islamic University Chittagong

2025
Finalist - BCS ICT FEST 2025 (Top 21 of 150+ Teams)

Bangladesh Computer Society

2025
Ranked 246th out of 760 Participants - KnightCTF 2025

Organized by Knight Squad

2025
2nd Runner-Up - IEEE CS Hackathon

IEEE Computer Society, Bangladesh University of Engineering and Technology

2024
Local Qualifier - NASA Space Apps Challenge 2024

Earth Science Division, Science Mission Directorate, NASA

2024
Ranked 26th out of 106 Teams - SMP CTF 2024

Organized by SMP Cyber Security

2024
1st Place - AutoCAD Design Competition

Department of Water Resources Engineering, Chittagong University of Engineering and Technology

2023

Volunteer Experience

WRROJoint Research Secretary, 2025-Present
NogorfulICT Director, 2024-Present
OngkoFounder and President, 2019-2020

Connect

I'm open to research, engineering, GIS, and interdisciplinary collaboration.