Unclecheng-li
24 exploits
Active since Feb 2026
JIT miscompilation in the JavaScript Engine: JIT component
rtmutex: Use waiter::task instead of current in remove_waiter()
KVM: x86: Fix shadow paging use-after-free due to unexpected role
Heap out-of-bounds write via odd slice_height in FFmpeg MagicYUV decoder
net/sched: fix pedit partial COW leading to page cache corruption
rxrpc: fix oversized RESPONSE authenticator length check
Nezha Monitoring: Pre-auth path traversal via /dashboard.. prefix confusion leaks jwt_secret_key
LiteLLM < 1.83.14 Privilege Escalation via API Key Generation
Apache HTTP Server: mod_http2 denial of service
smb: client: reject userspace cifs.spnego descriptions
Notepad++ 8.9.6 - Arbitrary Code Execution
redis-server RESTORE invalid memory access may allow remote code execution
cPanel 11.120.0.0-11.136.0.9 Arbitrary File Read via cpdavd
net: skbuff: propagate shared-frag marker through frag-transfer helpers
net: skb: fix cross-cache free of KFENCE-allocated skb head
Valkey 9.0.0-9.0.3 - Denial of Service via Empty Request Handling
Google Chrome <145.0.7632.75 - Use After Free
rxrpc: fix oversized RESPONSE authenticator length check
net/rds: reset op_nents when zerocopy page pin fails
NGINX Plus and NGINX Open Source - Heap-based Buffer Overflow in ngx_http_rewrite_module
ptrace: slightly saner 'get_dumpable()' logic
rxrpc: Also unshare DATA/RESPONSE packets when paged frags are present
xfrm: esp: avoid in-place decrypt on shared skb frags
crypto: algif_aead - Revert to operating out-of-place