ri

19 exploits Active since Jan 2026
CVE-2026-23008 GITHUB MEDIUM solidity WORKING POC
Linux kernel - Null Pointer Dereference
In the Linux kernel, the following vulnerability has been resolved: drm/vmwgfx: Fix KMS with 3D on HW version 10 HW version 10 does not have GB Surfaces so there is no backing buffer for surface backed FBs. This would result in a nullptr dereference and crash the driver causing a black screen.
CVSS 5.5
CVE-2026-22018 GITHUB LOW python WORKING POC
Oracle Java SE & GraalVM DoS via Libraries (8u481, 11.0.30, 17.0.18, 21.0.10, 25.0.2, 26)
Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Libraries). Supported versions that are affected are Oracle Java SE: 8u481, 8u481-b50, 8u481-perf, 11.0.30, 17.0.18, 21.0.10, 25.0.2, 26; Oracle GraalVM for JDK: 17.0.18 and 21.0.10; Oracle GraalVM Enterprise Edition: 21.3.17. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition. Note: This vulnerability can be exploited by using APIs in the specified Component, e.g., through a web service which supplies data to the APIs. This vulnerability also applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. CVSS 3.1 Base Score 3.7 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L).
CVSS 3.7
CVE-2026-22014 NOMISEC LOW WORKING POC
Oracle User Management 12.2.7-12.2.15 - Privilege Escalation
Vulnerability in the Oracle User Management product of Oracle E-Business Suite (component: Workflow and Business Events). Supported versions that are affected are 12.2.7-12.2.15. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle User Management. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle User Management accessible data as well as unauthorized read access to a subset of Oracle User Management accessible data. CVSS 3.1 Base Score 3.8 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:N).
CVSS 3.8
CVE-2026-21010 GITHUB MEDIUM python WORKING POC
Samsung Mobile Devices - Privilege Escalation
Improper input validation in Retail Mode prior to SMR Apr-2026 Release 1 allows local attackers to trigger privileged functions.
CVSS 6.6
CVE-2026-21003 GITHUB MEDIUM javascript WORKING POC
Samsung Mobile Devices - Auth Bypass
Improper input validation in data related to network restrictions prior to SMR Apr-2026 Release 1 allows physical attackers to bypass the restrictions.
CVSS 6.8
CVE-2026-21012 GITHUB LOW rust WORKING POC
Samsung Mobile Devices - Privilege Escalation
External control of file name in AODManager prior to SMR Apr-2026 Release 1 allows privileged local attacker to create file with system privilege.
CVSS 3.3
CVE-2026-21009 GITHUB MEDIUM python WORKING POC
Samsung Mobile Devices - App Pinning Bypass
Improper check for exceptional conditions in Recents prior to SMR Apr-2026 Release 1 allows physical attacker to bypass App Pinning.
CVSS 6.8
CVE-2026-11119 NOMISEC CRITICAL WORKING POC
Google Chrome - Improper Input Validation
Inappropriate implementation in GPU in Google Chrome on Android prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium)
CVSS 9.6
CVE-2026-11112 NOMISEC CRITICAL WORKING POC
Google Chrome - Improper Input Validation
Insufficient validation of untrusted input in Chromoting in Google Chrome on Linux prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted Chrome Extension. (Chromium security severity: Medium)
CVSS 9.6
CVE-2026-11103 GITHUB HIGH javascript WORKING POC
Google Chrome - Privilege Escalation
Inappropriate implementation in Installer in Google Chrome on Windows prior to 149.0.7827.53 allowed a local attacker to perform OS-level privilege escalation via a malicious file. (Chromium security severity: Medium)
CVSS 7.8
CVE-2026-11107 GITHUB MEDIUM python WORKING POC
Google Chrome < 149.0.7827.53 - UI Spoofing via Crafted HTML Page
Inappropriate implementation in Downloads in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium)
CVSS 4.3
CVE-2026-11106 GITHUB MEDIUM python WORKING POC
Google Chrome < 149.0.7827.53 - Cross-Origin Data Leak via Media Component
Inappropriate implementation in Media in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)
CVSS 6.5
CVE-2026-1010 GITHUB HIGH python WORKING POC
Altium On-Prem Enterprise Server - Authenticated Stored Cross-Site Scripting via Workflow Form Submission
A stored cross-site scripting (XSS) vulnerability exists in the Altium Workflow Engine due to missing server-side input sanitization in workflow form submission APIs. A regular authenticated user can inject arbitrary JavaScript into workflow data. When an administrator views the affected workflow, the injected payload executes in the administrator’s browser context, allowing privilege escalation, including creation of new administrator accounts, session token theft, and execution of administrative actions.
CVSS 8.0
CVE-2026-8888 GITHUB HIGH python WORKING POC
Securly Chrome Extension < 3.0.7 - Denial of Service
Version 3.0.7 of the Securly Chrome Extension downloads config.json over HTTP and compiles server-provided patterns as JavaScript regular expressions via new RegExp() without complexity validation. An on-path attacker can inject specific patterns to cause catastrophic backtracking, resulting in denial of service on all browsing.
CVSS 7.5
CVE-2026-6666 GITHUB MEDIUM python WORKING POC
PgBouncer crash in kill_pool_logins_server_error
A possible null pointer reference in PgBouncer before 1.25.2 could lead to a crash, if a server sends an error response without SQLSTATE field.
CVSS 5.9
CVE-2026-2020 GITHUB HIGH python WORKING POC
WordPress JS Archive List <=6.1.7 - Deserialization
The JS Archive List plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 6.1.7 via the 'included' shortcode attribute. This is due to the deserialization of untrusted input supplied via the 'included' parameter of the plugin's shortcode. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject a PHP Object. No known POP chain is present in the vulnerable software. If a POP chain is present via an additional plugin or theme installed on the target system, it could allow the attacker to delete arbitrary files, retrieve sensitive data, or execute code.
CVSS 7.5
CVE-2026-4567 NOMISEC CRITICAL WORKING POC
Tenda A15 UploadCfg stack-based overflow
A vulnerability has been found in Tenda A15 15.13.07.13. The impacted element is the function UploadCfg of the file /cgi-bin/UploadCfg. The manipulation of the argument File leads to stack-based buffer overflow. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.
CVSS 9.8
CVE-2026-9999 NOMISEC HIGH WORKING POC
Google Chrome - Arbitrary Code Execution
Inappropriate implementation in ANGLE in Google Chrome on Mac prior to 148.0.7778.216 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
CVSS 8.8
CVE-2026-1337 NOMISEC MEDIUM WORKING POC
Neo4j < 2026.01 - Cross-Site Scripting via Query Log Unicode Character Escaping
Insufficient escaping of unicode characters in query log in Neo4j Enterprise and Community editions prior to 2026.01 can lead to XSS if the user opens the logs in a tool that treats them as HTML. There is no security impact on Neo4j products, but this advisory is released as a precaution to treat the logs as plain text if using versions prior to 2026.01. Proof of concept exploit:  https://github.com/JoakimBulow/CVE-2026-1337
CVSS 5.4