PoC Archive PoC Archive

binary PoCs

subscribe (RSS)

Proof-of-concept research filed under the binary category.

Entries

119

in binary

CISA KEV

12

exploited in the wild

Ransomware

5

known campaign use

Unpatched

62

no vendor fix

Critical

27

23% of listed

119 entries

Severity

Exploitation signals

Patch status

Date range

Sort

119 result(s)

binary list (119 shown)
of 119 indexed
  • CVE-2026-21508 binary HIGH 7.8

    Windows Media Player DLL Hijack -- Local Privilege Escalation (CVE-2026-21508)

    CVE-2026-21508 is a DLL hijacking vulnerability that achieves Session 0 privilege escalation on Windows 11. WUDFHost.exe loads CrossDevice.Streaming.Source.dll from the user-writable path C:\ProgramData\CrossDevice\. By planting a malicious DLL and…

    Patched 2026-08-16
  • CVE-2026-68398 binary HIGH 7.8

    Ubuntu Linux Kernel PPPoL2TP Use-After-Free Local Privilege Escalation (CVE-2026-68398)

    CVE-2026-68398 is a use-after-free race condition between PPPoL2TP receive processing and destruction of a bound-but-unattached PPP channel in the Linux kernel. The PPPoX socket and its embedded pppchannel are RCU-safe, but the internal struct channel used by…

    Patched 2026-08-16
  • CVE-2026-23111 binary HIGH 7.8

    Linux nf_tables Catchall Set Element UAF -- Local Privilege Escalation (CVE-2026-23111)

    CVE-2026-23111 is a use-after-free in the Linux nftables subsystem caused by an inverted genmask check in nftmapcatchallactivate(). During transaction abort, the handler skips inactive catchall elements that need reactivation and processes active ones that do…

    Unverified 2026-08-16
  • CVE-2026-53361 binary CRITICAL 9.8

    Linux AF_UNIX GC vs MSG_PEEK Use-After-Free Container Escape (CVE-2026-53361)

    CVE-2026-53361 is a use-after-free in the Linux AFUNIX socket garbage collector triggered via a MSGPEEK race. The GC reclaims in-flight sockets forming unreachable reference cycles, but a concurrent MSGPEEK can take a reference the GC census never counts. The…

    Unverified 2026-08-16
  • CVE-2026-2764 / MFSA 2026-13 binary HIGH 8.8

    Firefox SpiderMonkey JIT Miscompilation and Use-After-Free (CVE-2026-2764)

    CVE-2026-2764 is a JIT miscompilation vulnerability in Firefox SpiderMonkey (IonMonkey/Baseline) that leads to type confusion and use-after-free. On new Ctor(...arr) / Reflect.construct with a Proxy as newTarget, the proxy get trap fires while the engine is…

    Unverified 2026-08-16
  • CVE-2026-64564 binary HIGH 7.8

    Linux Kernel — SCTPhantom: SCTP ASCONF DEL-IP Use-After-Free Local Privilege Escalation (CVE-2026-64564)

    CVE-2026-64564 is a use-after-free vulnerability in the Linux kernel SCTP ASCONF DEL-IP processing. When a multihomed SCTP association processes an ASCONF chunk that deletes an IP address, the associated transport structure is freed but a dangling pointer…

    Unverified 2026-08-15
  • CVE-2026-68138 binary HIGH 7.8

    Linux Kernel — qdisc Rate-Table Race Condition Local Privilege Escalation (CVE-2026-68138)

    CVE-2026-68138 is a race condition in the Linux kernel traffic-control rate-table code that leads to a use-after-free or double-free of struct qdiscratetable. The flower classifier sets TCFPROTOOPSDOITUNLOCKED, allowing RTMNEWTFILTER requests to reach…

    Patched 2026-08-15
  • CVE-2026-64531 binary HIGH 7.8

    Linux Kernel — OVSwrap: Open vSwitch Conntrack Local Privilege Escalation (CVE-2026-64531)

    CVE-2026-64531 is a memory corruption vulnerability in the Linux kernel Open vSwitch (OVS) conntrack subsystem. The exploit, named OVSwrap, uses OVS Generic Netlink operations to corrupt conntrack timeout and labels carrier objects, establishing kernel read…

    Unverified 2026-08-15
  • CVE-2026-17106 binary CRITICAL 9.8

    Docker — CopyEscape: Container-to-Host Escape via docker cp Race Condition (CVE-2026-17106)

    CVE-2026-17106, nicknamed CopyEscape, is a race condition in Docker's docker cp command that allows a malicious running container to escape and write arbitrary files on the Docker host. The vulnerability exists in how Docker's archive producer walks the…

    Unverified 2026-08-15
  • Bypass of CVE-2026-50656 binary HIGH 7.8 EPSS 11%

    Windows Defender — ShieldBreak: RoguePlanet (CVE-2026-50656) Patch Bypass via Cloud Files Rehydration + Object Manager Symlinks

    ShieldBreak is a 0-day local privilege escalation exploit that bypasses the patch for CVE-2026-50656 (RoguePlanet), achieving SYSTEM-level code execution from an unprivileged user on fully patched Windows 11 and Server 2025 systems. The exploit was released…

    Unpatched 2026-08-11
  • CVE-2026-64561 binary HIGH 8.8

    Zapscape — KVM/x86 Shadow-MMU Recursive-Zap Guest-to-Host Escape (CVE-2026-64561)

    Zapscape (CVE-2026-64561) is a use-after-free in the KVM/x86 shadow MMU that lets a guest which uses nested virtualization escape to the host and run commands as the host kernel (root). Using guest-side actions alone, an attacker makes KVM recursively zap a…

    Patched 2026-08-09
  • MDEV-40328 binary CRITICAL 8.8

    MariaDB — Low-Privilege Remote Code Execution via ST_Area OOB Read + SYS_REFCURSOR Use-After-Free

    This PoC chains two MariaDB memory-safety bugs to achieve remote code execution as the mariadbd process from a low-privilege database account — no special grants, no filesystem access, no administrative role:

    Unpatched 2026-08-09
  • NotCVE-2026-0010 binary HIGH

    Barrier 2.4.0 — barrierd.exe Unauthenticated IPC → SYSTEM Privilege Escalation (NotCVE-2026-0010)

    Barrier 2.4.0 ships a Windows service daemon (barrierd.exe) that runs as LocalSystem and binds a TCP IPC control server on 127.0.0.1:24801 with no authentication. Any local process, regardless of privilege level, can connect to that port and send a…

    Unverified 2026-08-01
  • CVE-2026-49176 binary HIGH 7.8

    Windows WalletService Known-Folder Redirection → ESE Persisted-Callback DLL Load Local Privilege Escalation (CVE-2026-49176)

    Windows WalletService — which runs as LocalSystem — resolves the caller's FOLDERIDDocuments known folder while impersonating the calling user, then reverts to the LocalSystem token before opening <Documents>\Wallet\wallet.db. Because the folder resolution…

    Patched 2026-07-27
  • CVE-2026-46316 binary CRITICAL 9.3

    ITScape — KVM/arm64 vGIC-ITS Guest-to-Host VM Escape (CVE-2026-46316)

    ITScape (CVE-2026-46316) is a use-after-free in the KVM/arm64 in-kernel vGIC-ITS (Interrupt Translation Service) emulation that lets an unprivileged-but-rooted guest VM escape to the host and execute code as the host kernel (i.e., as root on the host), on any…

    Patched 2026-07-27
  • N/A binary HIGH

    GreatXML — WinRE / Defender Offline-Scan Trust-Boundary Abuse → BitLocker Bypass (No CVE)

    GreatXML abuses the trust boundary around Microsoft Defender's Offline Scan feature, which reboots a Windows machine into WinRE (Windows PE) and runs OfflineScannerShell.exe with elevated, pre-BitLocker-unlock trust. The ReAgent.xml recovery-configuration…

    Unpatched 2026-07-27
  • CVE-2026-14431 binary HIGH 8.8

    V8 Array Iterator Maglev Type Confusion — addrof/fakeobj Primitives (CVE-2026-14431)

    Array.prototypeSymbol.iterator.next() is miscompiled by V8's Maglev JIT tier: ArrayIteratorPrototypeNext fails to re-check the map (elements kind) of an inlined array after a side effect can change it mid-call, leading to a type confusion between…

    Unpatched 2026-07-19
  • binary HIGH

    LegacyHive - Windows user profile service arbitrary hive load elevation of privileges vulnerability

    LegacyHive demonstrates a local privilege-escalation path in Windows user profile hive handling where a low-privileged user can influence how another user's hive is loaded. The PoC modifies hive data and abuses object manager links and an oplock timing window…

    Patched 2026-07-19
  • CVE-2026-43499 binary HIGH 7.8

    Linux Kernel rtmutex Priority-Inheritance Stack-UAF — "GhostLock" (CVE-2026-43499, Nebula Security weaponized variant)

    Nebula Security independently discovered and weaponized a use-after-free in the Linux kernel's rtmutex priority-inheritance cleanup logic, naming it "GhostLock." They describe it as a stack-UAF reachable via ordinary threading/futex calls from any…

    Patched 2026-07-08
  • CVE-2025-32463 binary CRITICAL 9.3 KEV EPSS 56%

    Sudo `chroot` Option Local Privilege Escalation (CVE-2025-32463)

    Sudo's -R/--chroot option allowed an unprivileged local user to make sudo chroot() into a directory the user controls before sudo resolves and loads NSS (Name Service Switch) configuration and modules. Because sudo continues to consult /etc/nsswitch.conf and…

    Patched 2026-07-06
  • CVE-2025-49844 binary CRITICAL 9.9 EPSS 87%

    RediShell: Redis Lua Scripting Use-After-Free Leading to JOP-Chained Remote Code Execution (CVE-2025-49844)

    CVE-2025-49844 ("RediShell") is a use-after-free vulnerability in Redis's embedded Lua scripting engine: a crafted Lua script can manipulate the Lua garbage collector so that a Proto (function prototype) object is freed while a reference to it is still…

    Patched 2026-07-06
  • CVE-2025-54957 binary CRITICAL 9.8

    Dolby Unified (DDPlus) Decoder Out-of-Bounds Write via Evolution Data (CVE-2025-54957)

    CVE-2025-54957 is a critical out-of-bounds write vulnerability in Dolby's DDPlus Unified Decoder, triggered while processing "evolution" data in an AC-3/EC-3 (Dolby Digital Plus) bitstream. An integer overflow in the length calculation for evolution-data…

    Unverified 2026-07-06
  • CVE-2026-20698 binary HIGH

    XNU PF_ROUTE RTA_GENMASK Heap Buffer Overflow (CVE-2026-20698)

    XNU's routing socket implementation processes RTMGET messages carrying an RTAGENMASK sockaddr through rnaddmask(), which copies the supplied genmask into a fixed, address-family-dependent radix-tree node buffer without validating that the attacker-controlled…

    Patched 2026-07-05
  • CVE-2026-3609 binary HIGH

    XIGNCODE3 Anti-Cheat Driver PPL-Bypass LSASS Credential Dump (CVE-2026-3609)

    Wellbia's XIGNCODE3 anti-cheat kernel driver xhunter1.sys exposes an IRPMJWRITE command interface that calls ObOpenObjectByPointer with AccessMode = KernelMode and without the OBJKERNELHANDLE flag, handing a kernel-minted PROCESSALLACCESS handle straight into…

    Patched 2026-07-05
  • CVE-2026-32202 binary HIGH KEV EPSS 64%

    Windows Shell LNK _IDCONTROLW Zero-Click SMB Coercion Builder — CVE-2026-32202

    This repository documents a reverse-engineered, undocumented IDCONTROLW structure used internally by shell32.dll to represent Control Panel applet items inside a .lnk file's LinkTargetIDList, based on the researcher's own IDA Pro static analysis and…

    Unverified 2026-07-05
  • CVE-2026-26179 / ZDI-26-276 binary HIGH

    Windows Secure Kernel (VTL1/VSM) Memory Corruption PoC (CVE-2026-26179 / ZDI-26-276)

    CVE-2026-26179 is a vulnerability discovered by the author within the Windows Secure Kernel — the isolated, more privileged execution environment (VTL1) that underlies Virtualization Based Security (VBS) features such as Credential Guard and HVCI. The author…

    Unverified 2026-07-05
  • CVE-2026-42978 binary HIGH 7.8

    Windows Push Notification Service Use-After-Free Race (CVE-2026-42978)

    CVE-2026-42978 is a use-after-free race condition (CWE-362) in wpncore.dll's PresentationEndpointFacade class, which backs the WpnService Windows Push Notification service running as NT AUTHORITY\SYSTEM. Facade methods (e.g. ToastUnblockAll) fetch a pointer…

    Unverified 2026-07-05
  • CVE-2026-29923 binary CRITICAL

    Windows pstrip64.sys BYOVD Physical Memory Local Privilege Escalation — CVE-2026-29923

    pstrip64.sys is a legacy signed kernel driver bundled with EnTech Taiwan PowerStrip that exposes an IOCTL (0x80002008) allowing a calling process to map arbitrary physical memory into its own address space via ZwMapViewOfSection against…

    Unverified 2026-07-05
  • CVE-2026-40369 binary HIGH

    Windows Kernel Local Privilege Escalation via SeDebugPrivilege Bit Corruption (CVE-2026-40369)

    This exploit is a local privilege escalation chain against the Windows kernel that abuses a low-level primitive reachable through NtQuerySystemInformation to corrupt a bit near the process's SeDebugPrivilege state in kernel memory, without requiring the…

    Unverified 2026-07-05
  • CVE-2026-49160 binary HIGH EPSS 54%

    Windows HTTP.sys Header-Count-Triggered Kernel Memory Corruption / BSOD (CVE-2026-49160)

    This PoC targets a memory-safety bug in the Windows HTTP.sys kernel driver's request header parsing path (HTTP!UlpParseNextRequest / HTTP!UlpHandleRequest). The included http2bomb.py script establishes a TLS/HTTP2 connection to a target IIS/HTTP.sys-backed…

    Patched 2026-07-05
  • CVE-2026-20817 binary HIGH

    Windows Error Reporting Service ALPC Local Privilege Escalation (CVE-2026-20817)

    CVE-2026-20817 abuses an ALPC-based elevation primitive in the Windows Error Reporting Service. WerSvc listens on the \WindowsErrorReportingServicePort ALPC port and, upon receiving a specially crafted WERSVCMSG request with the SvcElevatedLaunch message flag…

    Unverified 2026-07-05
  • CVE-2026-2636 binary MEDIUM

    Windows CLFS.sys Unrecoverable State / BSoD via ReadFile on Log File Handle (CVE-2026-2636)

    CVE-2026-2636 is a denial-of-service vulnerability in the Windows Common Log File System driver (CLFS.sys). An unprivileged local user can crash the system simply by calling the ReadFile Win32 API on a handle obtained via CreateLogFile — a call sequence CLFS…

    Patched 2026-07-05
  • CVE-2026-35250 binary LOW 2.3

    VirtualBox DevVGA_VBVA Integer Overflow leading to Guest-Triggerable DoS (CVE-2026-35250)

    VirtualBox's DevVGAVBVA.cpp dimension-validation check uses a logical OR where an AND is required, letting a malicious guest supply width=0x80000001, height=16 and pass the bounds check. The resulting pointer-data size calculation (cbPointerData) then…

    Unverified 2026-07-05
  • CVE-2026-44656 binary HIGH

    Vim Modeline `path` Option Backtick-Expansion Command Injection (CVE-2026-44656)

    Vim's modeline processing allows a file to set the path option, which can itself contain a backtick ( ) expansion expression. When a user triggers path/file completion via the :find command and presses Tab, Vim evaluates the path option's embedded backtick…

    Patched 2026-07-05
  • CVE-2026-6307 binary CRITICAL

    V8 JavaScript Engine Exploit — "Longinus" Kit (CVE-2026-6307)

    A full V8 exploit kit targeting CVE-2026-6307, comprising a JavaScript trigger/exploit (poc.js), Python generation and validation tooling (gen.py, val.py) for producing and testing exploit payload variants, and a YARA detection rule for the resulting…

    Unverified 2026-07-05
  • CVE-2026-3888 binary HIGH

    snapd snap-confine / systemd-tmpfiles Race Condition LPE (CVE-2026-3888)

    snap-confine's writable-mimic setup performs a directory swap while constructing a snap's mount namespace, and races with systemd-tmpfiles during this window. A local attacker can exploit this race to poison the namespace being constructed for a privileged…

    Patched 2026-07-05
  • CVE-2026-21018 binary HIGH

    Samsung SveService Native Out-of-Bounds Write (CVE-2026-21018)

    CVE-2026-21018 is an out-of-bounds write in the Samsung system service SveService, which runs as system (UID 1000) and is registered directly via ServiceManager.addService() — bypassing Android's normal signatureOrSystem permission enforcement, so it is…

    Unverified 2026-07-05
  • CVE-2026-20980 binary CRITICAL

    Samsung Android AT-Command Filter Bypass to system_server Code Execution (CVE-2026-20980)

    CVE-2026-20980 is the first stage of a three-bug exploit chain against Samsung's AP AT-command handling. The atdistributor daemon filters "protected" AT commands via libpacmclient.so's pacmcheckatcmds, which rejects multi-command payloads by checking for the…

    Unverified 2026-07-05
  • CVE-2026-27831 binary MEDIUM

    rldns 1.3 Heap-Based Out-of-Bounds Read Remote DoS (CVE-2026-27831)

    rldns is an open-source DNS server for Linux, FreeBSD, and NetBSD. Version 1.3 contains a heap-based out-of-bounds read that can be triggered remotely by sending a specially crafted, malformed DNS-like UDP packet, causing the server process to crash and…

    Patched 2026-07-05
  • CVE-2026-2005 binary CRITICAL

    PostgreSQL pgcrypto PGP Heap Overflow to Superuser Escalation — CVE-2026-2005

    The pgcrypto extension's PGP session-key parsing contains a heap-based buffer overflow that corrupts MBuf structure headers used internally to track ciphertext/plaintext buffers. By crafting malicious PGP messages passed to pgcrypto decryption functions, a…

    Unverified 2026-07-05
  • CVE-2026-3437 binary HIGH

    Portwell Engineering Toolkits Driver Arbitrary Physical Memory R/W LPE (CVE-2026-3437)

    portwell.sys, a legitimately signed driver shipped with Portwell Engineering Toolkits v4.8.2, exposes IOCTL handlers that let any local user-mode process read and write arbitrary physical memory via MmMapIoSpace, with no validation of the caller-supplied…

    Unverified 2026-07-05
  • CVE-2026-43494 binary HIGH

    PinTheft: RDS zcopy Refcount-Steal Double-Free LPE — Pure NASM Rewrite (CVE-2026-43494)

    This is a hand-written, dependency-free x86-64 NASM rewrite of the "PinTheft" Linux local privilege escalation exploit (originally published as PinTheft-go). It targets a refcount double-drop in the RDS zerocopy send path (rdsmessagezcopyfromuser()), which is…

    Patched 2026-07-05
  • CVE-2026-14459 binary HIGH 8.8

    Pardus Software Center Local Privilege Escalation via APT Option Injection (CVE-2026-14459 / CVE-2026-14460)

    Two local privilege-escalation flaws affect the pardus-software package that powers the Pardus Software Center's PolicyKit-mediated install/update helpers. CVE-2026-14459 (CWE-88, argument injection) arises because the privileged Actions.py helper splits its…

    Patched 2026-07-05
  • CVE-2026-41651 binary HIGH

    PackageKit TOCTOU Local Privilege Escalation (CVE-2026-41651)

    PackageKit's transaction handling in src/pk-transaction.c contains a set of logic flaws that combine into a TOCTOU (time-of-check to time-of-use) race condition, nicknamed "Pack2TheRoot" by the researcher. InstallFiles() overwrites cached transaction…

    Patched 2026-07-05
  • CVE-2026-21986 binary MEDIUM 7.1

    Oracle VirtualBox Shared Folders Kernel Memory Exhaustion DoS (CVE-2026-21986)

    CVE-2026-21986 is a denial-of-service vulnerability in the VirtualBox Shared Folders driver interface exposed to Windows guests as the device \\.\VBoxMiniRdrDN. The driver's IOCTLMRXVBOXADDCONN handler accepts user-controlled connection-string buffers and…

    Patched 2026-07-05
  • CVE-2026-33317 binary HIGH 8.7

    OP-TEE PKCS#11 TA Out-of-Bounds Heap Write via `C_GetAttributeValue` (CVE-2026-33317)

    CVE-2026-33317 is missing bounds validation in entrygetattributevalue() in the OP-TEE PKCS#11 Trusted Application, reachable via the PKCS11CMDGETATTRIBUTEVALUE command. The TA does not verify that each attribute header and its associated data region lie fully…

    Patched 2026-07-05
  • CVE-2026-3008 binary MEDIUM

    Notepad++ nativeLang.xml Format String Crash / Info Disclosure — CVE-2026-3008

    Notepad++'s Find Results panel initializer (sub1400916C0) retrieves the localized find-result-hits string from nativeLang.xml and passes it directly as the format string argument to wsprintfW, with no accompanying variadic data arguments and no validation of…

    Unverified 2026-07-05
  • CVE-2026-1668 binary CRITICAL

    MIPS-Based Managed Switch Firmware Pre-Auth Kernel RCE — CVE-2026-1668

    The switch's embedded web management HTTP server contains a memory-corruption flaw reachable via a crafted request to the /data/login.json endpoint, exploitable before the device's first legitimate HTTP request after boot. The PoC builds a raw MIPS shellcode…

    Unverified 2026-07-05
  • CVE-2026-36981 binary HIGH

    MiniTool pwdrvio.sys Kernel Write-What-Where — Local Privilege Escalation Primitive (CVE-2026-36981)

    MiniTool's pwdrvio.sys kernel driver exposes a write-what-where condition through its IOCTL interface, allowing an unprivileged local attacker to write attacker-controlled data to an attacker-controlled kernel address. The included PoC demonstrates a…

    Patched 2026-07-05
  • CVE-2026-36980 binary MEDIUM

    MiniTool pwdrvio.sys Kernel Driver Buffer Overflow — Local DoS/BSOD (CVE-2026-36980)

    MiniTool's pwdrvio.sys kernel driver contains a buffer overflow in its IOCTL handler. An unprivileged local attacker can send a crafted IOCTL request that corrupts kernel pool memory, triggering an immediate system crash (BSOD) — a local denial-of-service…

    Patched 2026-07-05
  • CVE-2026-41091 binary HIGH 7.8 KEV

    Microsoft Defender Link Following Local Privilege Escalation (CVE-2026-41091)

    CVE-2026-41091 is a local privilege escalation vulnerability in Microsoft Defender caused by improper link resolution (CWE-59) during file operations performed with SYSTEM privileges. By racing a Defender-triggered scan against filesystem oplocks, and then…

    Unpatched 2026-07-05
  • CVE-2026-32710 binary CRITICAL

    MariaDB JSON_SCHEMA_VALID() Heap Overflow — Privilege Escalation to UDF RCE (CVE-2026-32710)

    MariaDB's jsongetnormalizedstring() (used by JSONSCHEMAVALID(), sql/jsonschemahelper.cc:91) performs an unbounded strncpy of up to 192 bytes into a 128-byte DYNAMICSTRING buffer, producing a heap out-of-bounds write. The included exploit chains this overflow…

    Patched 2026-07-05
  • CVE-2026-53075 binary INFO

    Linux Kernel PPP Unprivileged User-Namespace Precondition Probe — CVE-2026-53075

    This is a small local diagnostic probe, not a full weaponized exploit. It checks whether the preconditions for CVE-2026-53075 (an unprivileged-user attack path against the kernel ppp driver) are present on the running kernel: it creates an unprivileged…

    Patched 2026-07-05
  • CVE-2026-23416 binary MEDIUM

    Linux Kernel mm/mseal VMA-Merge Stale-Bound Bug (CVE-2026-23416)

    CVE-2026-23416 is a logic bug in the kernel's mseal(2) implementation. msealapply() iterates over the target VMAs and advances its cursor by copying a previously-captured vmend value, but the underlying vmamodifyflags() call can merge adjacent VMAs…

    Patched 2026-07-05
  • CVE-2026-31429 binary MEDIUM

    Linux Kernel KFENCE Cross-Cache Free of SKB Head via bpf_prog_test_run_skb — CVE-2026-31429

    Linux's skbkfreehead() decides which slab cache to free an SKB's head buffer back to based solely on whether endoffset equals SKBSMALLHEADHEADROOM, relying on the fact that SKBSMALLHEADCACHESIZE is a non-power-of-2 value that normally never collides with a…

    Patched 2026-07-05
  • CVE-2026-43499 binary HIGH 7.8

    Linux Kernel Futex-PI rtmutex remove_waiter() Use-After-Free (CVE-2026-43499)

    CVE-2026-43499 is a use-after-free in the Linux kernel's removewaiter() function (kernel/locking/rtmutex.c), which is shared between the ordinary rtmutex slow-unlock path and the futex priority-inheritance (PI) proxy-lock rollback path invoked from…

    Patched 2026-07-05
  • CVE-2026-31694 binary HIGH

    Linux FUSE Readdir Cache Out-of-Bounds Write to Root LPE — CVE-2026-31694

    fuseadddirenttocache() is missing a bounds check when copying a FUSE server-supplied directory entry into the kernel's readdir page-cache. A malicious (or attacker-controlled) FUSE server can return a dirent with namelen = 4095, which serializes to a…

    Patched 2026-07-05
  • CVE-2026-31413 binary CRITICAL

    Linux BPF Verifier Scalar-Forking Soundness Bug to Container Escape — CVE-2026-31413

    The Linux BPF verifier's maybeforkscalars() forks verifier state when it sees an ARSH followed by AND/OR with a constant. The forked ("pushed") path is generated via pushstack(env, env->insnidx + 1, ...), which skips the ALU instruction on that path and…

    Patched 2026-07-05
  • CVE-2026-36834 binary MEDIUM 6.5

    LibRaw pana8.cpp GetDBit() Out-of-Bounds Array Read (CVE-2026-36834)

    LibRaw's GetDBit() function, used when decoding Panasonic RW2 raw image files, can return the value 17 when no Huffman table match is found. However, the huffcoeff[] array is declared with only 17 elements (valid indices 0-16), so this out-of-bounds return…

    Unverified 2026-07-05
  • CVE-2026-0006 binary CRITICAL 9.8

    libopenapv / Android APV Codec Zero-Click Heap Buffer Overflow (CVE-2026-0006)

    The APV decoder in libopenapv parses two different structures — an AUINFO PBU (Payload Byte Unit) and the actual FRAME PBU — to determine frame dimensions, but oapvdinfo() and oapvddecode() read those dimensions from different sources without cross-validating…

    Unverified 2026-07-05
  • CVE-2026-0827 binary HIGH

    Lenovo LDE (LdeApi.Server.exe) Unimpersonated Junction-Based Arbitrary File Write to SYSTEM (CVE-2026-0827)

    The Lenovo LDE service process LdeApi.Server.exe runs as SYSTEM and periodically writes a file named MP27AM7Westimation.json into C:\ProgramData\Lenovo\LDE\SYSTEM without impersonating the calling user and without verifying the target path is a real directory…

    Unverified 2026-07-05
  • CVE-2026-53360 binary HIGH

    KVM SEV-SNP Page State Change (PSC) Heap Out-of-Bounds — CVE-2026-53360

    KVM's SEV-SNP Page State Change (PSC) handler trusts a guest-supplied entry count against a fixed protocol constant (VMGEXITPSCMAXCOUNT = 253) instead of validating it against the actual size of the buffer the host allocated for the request. When a guest…

    Patched 2026-07-05
  • CVE-2026-0828 binary HIGH

    KillChain — Vulnerable Kernel Driver IOCTL Protected-Process Termination (CVE-2026-0828)

    KillChain is a fully-built "Bring Your Own Vulnerable Driver" (BYOVD) tool that embeds a vulnerable kernel driver, ProcessMonitorDriver.sys, directly inside its executable as a raw byte array. At runtime it extracts the driver to a temp path, registers it as…

    Unverified 2026-07-05
  • CVE-2026-28372 binary HIGH 7.4

    GNU inetutils telnetd Local Privilege Escalation via NEW-ENVIRON Injection — CVE-2026-28372

    GNU inetutils telnetd forwards client-controlled environment variables — negotiated via the Telnet NEW-ENVIRON option — to the login(1) process it spawns without adequately sanitizing them. On systems where the installed login (from util-linux) supports a…

    Patched 2026-07-05
  • CVE-2026-5201 binary HIGH 7.5

    gdk-pixbuf JPEG Loader Heap Buffer Overflow — CVE-2026-5201

    gdk-pixbuf's direct JPEG loading path (gdkpixbufjpegimageload / gdkpixbufrealjpegimageload in io-jpeg.c) allocates the output pixel buffer based on the expected number of color components (3 for RGB, 4 for CMYK) without validating that libjpeg's actual…

    Patched 2026-07-05
  • CVE-2026-45250 binary CRITICAL

    FreeBSD setcred(2) Kernel Stack Buffer Overflow — Local Privilege Escalation (CVE-2026-45250)

    kernsetcredcopyinsuppgroups() in sys/kern/kernprot.c uses sizeof(groups) where groups is declared as gidt , so the size expression evaluates to 8 bytes (pointer size) instead of the intended 4 bytes (sizeof(gidt)). When the supplementary-groups count is small…

    Unverified 2026-07-05
  • CVE-2026-49417 binary HIGH

    FreeBSD OSS /dev/dsp Stale Kernel-Stack Buffer Local Privilege Escalation (CVE-2026-49417)

    exp.c is a local FreeBSD kernel privilege-escalation exploit built around /dev/dsp (the OSS sound driver). It sprays hundreds of pthreads that call nanosleep() with distinctively tagged tvnsec values so their kernel stacks/return addresses are recognizable,…

    Unverified 2026-07-05
  • CVE-2026-49413 binary HIGH

    FreeBSD Linuxulator AT_SECURE=0 Local Privilege Escalation via LD_PRELOAD (CVE-2026-49413)

    exploit.c is a local privilege-escalation PoC targeting FreeBSD's Linux compatibility subsystem. It detects whether the Linuxulator is loaded and glibc's dynamic linker is present under /compat/linux/, locates a setuid-root Linux binary within that tree, and…

    Unverified 2026-07-05
  • CVE-2026-7270 binary CRITICAL

    FreeBSD exec_args_adjust_args() Out-of-Bounds memmove — Local Privilege Escalation via sshd Race (CVE-2026-7270)

    An operator-precedence bug in FreeBSD's execargsadjustargs() (present since 2013) computes a memmove size using + consume instead of - consume, causing the copy length to be roughly double the correct value. With a ~265KB argv[0] supplied via a shebang exec,…

    Unverified 2026-07-05
  • CVE-2026-45258 binary CRITICAL

    FreeBSD /dev/dsp (OSS) Negative-Offset mmap Kernel Memory Corruption LPE (CVE-2026-45258)

    This PoC targets a FreeBSD kernel local privilege escalation reachable through the OSS /dev/dsp audio device driver. By configuring device fragment sizes via ioctl(SNDCTLDSPSETFRAGMENT, ...) and then mmap-ing the device with a crafted negative file offset,…

    Unverified 2026-07-05
  • CVE-2026-24018 binary HIGH

    Fortinet FortiClientLinux VPN Config Symlink/Shared-Object Loading LPE — CVE-2026-24018

    FortiClientLinux allows a VPN connection profile to reference a custom pre/post-connect shared object (.so) file path that gets loaded by a component of the client running with elevated privileges. Because the path is followed without validating…

    Unverified 2026-07-05
  • CVE-2026-6770 binary MEDIUM

    Firefox/Tor Browser IndexedDB Ordering Fingerprint — CVE-2026-6770

    Prior to the fix, Firefox's indexedDB.databases() API returned database names in an implementation-specific (non-alphabetically-sorted) internal order rather than a canonical sorted order. Because this ordering can vary based on subtle…

    Unverified 2026-07-05
  • CVE-2026-3102 binary HIGH

    ExifTool Metadata Field Command Injection (macOS) — CVE-2026-3102

    The PoC demonstrates a command-injection pattern in ExifTool's metadata tag-copy workflow: a crafted DateTimeOriginal value containing shell metacharacters is written into an image's metadata, and when the image is later processed with -tagsFromFile ...…

    Patched 2026-07-05
  • CVE-2026-0776 binary HIGH 7.3

    Discord Desktop Client Uncontrolled Search Path Element / Local Code Execution (CVE-2026-0776)

    CVE-2026-0776 is an Uncontrolled Search Path Element (CWE-427) issue in the Discord Desktop Client on Windows: under certain conditions the Electron/Node.js runtime resolves and loads native/JS modules from a filesystem location that a local, unprivileged…

    Unverified 2026-07-05
  • CVE-2026-31635 binary HIGH

    DirtyDecrypt-Go — RxRPC rxgk Page-Cache Overwrite LPE (Go Port) — CVE-2026-31635

    This is a Go re-implementation ("port") of the original C dirtydecrypt PoC, now tracked as its own CVE (CVE-2026-31635). The bug is a missing skbcowdata() call in rxgkdecryptskb(): the krb5enc AEAD used by RxRPC's rxgk security class decrypts skb payload data…

    Patched 2026-07-05
  • CVE-2026-30332 binary HIGH

    Balena Etcher Windows TOCTOU Privilege Escalation — CVE-2026-30332

    Balena Etcher for Windows writes a temporary .cmd script (containing environment variables and the command to launch etcher-util.exe) to a user-writable temp directory and then executes it with elevated privileges via a UAC prompt. Because there is a time gap…

    Unverified 2026-07-05
  • CVE-2026-6643 binary CRITICAL

    ASUSTOR ADM vpnupload.cgi Format String / Stack Buffer Overflow RCE — CVE-2026-6643

    The ASUSTOR ADM NAS operating system's WireGuard config upload handler (vpnupload.cgi, uploadwireguard action) contains two chained memory-safety bugs. First, it JSON-encodes the parsed config and passes the result directly as the format string to printf(),…

    Unverified 2026-07-05
  • CVE-2026-1880 binary MEDIUM

    ASUS DriverHub Update TOCTOU Local Privilege Escalation — CVE-2026-1880

    ASUS DriverHub updates drivers by downloading a package, extracting it to C:\ProgramData\ASUS\AsusDriverHub\SupportTemp\<drivername>, and later launching setup.exe from that directory via ShellExecuteExW. Because the driver folder name can be predicted from…

    Patched 2026-07-05
  • CVE-2026-20637 binary HIGH

    AppleSEPKeyStore IOKit Use-After-Free (CVE-2026-20637)

    The AppleSEPKeyStore kernel driver exposes an IOKit user client (AppleKeyStore) whose command gate can be freed while still being accessed, producing a use-after-free. The PoC opens repeated IOServiceOpen connections while separate threads race…

    Patched 2026-07-05
  • CVE-2026-43655 binary HIGH

    AppleM2ScalerCSCDriver Shared Scheduler Use-After-Free (CVE-2026-43655)

    CVE-2026-43655 is a use-after-free in the AppleM2ScalerCSCDriver kernel driver's shared scaler-operation scheduler, reachable from a default-sandboxed iOS/iPadOS/macOS app with no special entitlements (only get-task-allow, no jailbreak or private…

    Unverified 2026-07-05
  • CVE-2026-20687 binary HIGH

    AppleJPEGDriver startDecoder Timeout Use-After-Free (CVE-2026-20687)

    AppleJPEGDriver's synchronous decode path (startDecodersync) can time out while a decode request is still referenced by a per-codec queue-node vector; on timeout the driver frees the request object but fails to remove its embedded queue-node pointer from that…

    Patched 2026-07-05
  • CVE-2026-0047 binary CRITICAL 8.4

    Android ActivityManagerService dumpBitmapsProto() Missing Permission Check (CVE-2026-0047)

    ActivityManagerService.dumpBitmapsProto() is missing an enforceCallingOrSelfPermission(DUMP) check that should gate access to a system-wide UI bitmap dump used for debugging. Because the method body executes fully before any permission is verified, any…

    Unpatched 2026-07-05
  • None assigned as of 2026-07-03 binary MEDIUM

    VLC Bundled FFmpeg VP9 Decoder Resolution-Change Heap Crash

    VLC 3.0.23's bundled FFmpeg VP9 decoder tracks per-frame slice-thread progress in an entries array sized from the superblock row count (sbrows) of the current frame. A crafted two-frame VP9 IVF file — a 64x64 first frame followed by a 64x8192 second frame…

    Unverified 2026-07-03
  • None assigned as of 2026-07-03 binary HIGH

    System Informer phsvc Trusted-Host Confused Deputy LPE

    System Informer's privileged helper process phsvc exposes an ALPC API port (\BaseNamedObjects\SiSvcApiPort) with a connect ACL open to Everyone, and authorizes connecting clients purely by checking whether the client's process image is generically…

    Unverified 2026-07-03
  • None assigned as of 2026-07-03 binary CRITICAL

    QEMU CXL Type-3 Mailbox Guest-to-Host Escape

    QEMU's CXL Type-3 mailbox command handling contains two related out-of-bounds issues: the GETLOG handler validates offset + length as a byte range but then uses offset as an array index into cci->cellog, and the SETFEATURE rank-sparing handler copies…

    Unverified 2026-07-03
  • None assigned as of 2026-07-03 binary HIGH

    Pillow ImageCms Mutable output_mode Heap OOB Write

    Pillow's ImageCms.buildTransform() creates a reusable LittleCMS-backed transform object and stores mutable inputmode/outputmode attributes on the Python wrapper. ImageCmsTransform.apply() trusts these mutable attributes both to validate image modes and to…

    Unverified 2026-07-03
  • None assigned as of 2026-07-03 binary MEDIUM

    objdump DLX ELF Backend Out-of-Bounds Write (Crash-to-Calc)

    objdump -g (debug-info dumping) against a crafted ELF/DLX object file triggers an out-of-bounds write in the DLX ELF backend's relocation-processing code, writing outside the intended debug section buffer. The researcher shapes the crafted relocation data so…

    Unverified 2026-07-03
  • None assigned as of 2026-07-03 binary CRITICAL 3.1

    Lunar Client Modrinth Explore Raw-HTML to Local Launcher Execution Chain

    The chain begins with Lunar Client's Explore feature rendering attacker-controlled Modrinth project Markdown (project body and version changelog) through ReactMarkdown with the rehypeRaw plugin and no observed HTML sanitizer, allowing raw HTML/script-capable…

    Unverified 2026-07-03
  • None assigned as of 2026-07-03 binary MEDIUM

    libarchive ZIP Declared-Size Boundary Bypass via debuginfod

    The PoC builds a stored ZIP64 archive entry whose declared uncompressed size field is 109 bytes while the actual inflated stream is 4 GiB + 109 bytes — crafted so the low 32 bits of the true length equal the advertised value (0x100000004 mod 2^32 == 4, offset…

    Unverified 2026-07-03
  • None assigned as of 2026-07-03 binary HIGH

    ImageMagick Ghostscript Delegate Search Path Hijack

    When ImageMagick converts PDF/PS/EPS-family inputs on Windows and cannot resolve a full path to Ghostscript, it falls back to invoking the bare executable name gswin64c.exe and launches it through the Windows process API with the application name left unset —…

    Unverified 2026-07-03
  • None assigned as of 2026-07-03 binary MEDIUM

    Ghidra 12.1.2 Conditional Swift Demangler ACE (plus TraceRMI RCE and SevenZipJBinding Reachability)

    This entry packages three conditional, defensively-scoped findings against Ghidra 12.1.2 rather than a single unconditional exploit. First, the Swift demangler analyzer builds and launches a swift-demangle executable from a program/analyzer-controlled tool…

    Unverified 2026-07-03
  • None assigned as of 2026-07-03 binary CRITICAL

    FFmpeg RASC Decoder DLTA Heap Out-of-Bounds Write

    FFmpeg's RASC decoder (decodedlta() in libavcodec/rasc.c) tracks a row cursor and only checks whether it has reached the end of the current row after certain operations, rather than before. Several DLTA run types (4, 7, 12, 13) perform 32-bit reads/writes at…

    Unpatched 2026-07-03
  • None assigned as of 2026-07-03 binary HIGH

    AnyDesk Printer Pipe COM Impersonation Local Privilege Escalation

    AnyDesk's local printer IPC worker creates a named pipe (\\.\pipe\adprinterpipe) with an ACL that grants access to Everyone, then accepts a message containing attacker-controlled COM marshaling bytes, unmarshals it into an IUnknown, queries for IStream, and…

    Unverified 2026-07-03
  • CVE-2026-46331 binary HIGH 7.8

    Linux Kernel act_pedit Partial COW Page-Cache LPE (CVE-2026-46331)

    CVE-2026-46331 is a local privilege escalation in the Linux kernel's net/sched/actpedit subsystem. The vulnerable function tcfpeditact() computes the writable Copy-on-Write (COW) region using a pre-calculated maximum hint (tcfpoffmaxhint) before the actual…

    Patched 2026-06-30
  • CVE-2026-8461 binary HIGH 8.8

    FFmpeg MagicYUV Decoder Out-of-Bounds Write / RCE — PixelSmash (CVE-2026-8461)

    CVE-2026-8461 (codename PixelSmash) is a High-severity out-of-bounds heap write in FFmpeg's MagicYUV decoder (libavcodec). Improper bounds validation during frame decoding allows a specially crafted video file with an odd slice height to trigger a heap buffer…

    Patched 2026-06-30
  • CVE-2026-7574 binary HIGH 8.7

    Claude Desktop Cowork VM Image Integrity Bypass / Local Persistence (CVE-2026-7574)

    CVE-2026-7574 is a VM image integrity bypass in Anthropic's Claude Desktop Cowork feature (macOS). Before booting the Cowork virtual machine, the application validates only the presence of rootfs.img and its associated version marker (.rootfs.img.origin); it…

    Unverified 2026-06-30
  • CVE-2026-45586 binary HIGH 7.8

    Windows CTFMON Arbitrary Section Object EoP — GreenPlasma (CVE-2026-45586)

    CVE-2026-45586 (GreenPlasma) is a Windows CTFMON Elevation of Privilege vulnerability exploiting an arbitrary named section object creation primitive. A standard unprivileged user can create a section object in any directory object writable by SYSTEM, abusing…

    Patched 2026-06-28
  • CVE-2026-43503 binary HIGH 8.8

    DirtyClone — Linux Kernel LPE via Cloned Packet Page-Cache Overwrite (CVE-2026-43503)

    DirtyClone (CVE-2026-43503, CVSS 8.8) is the fourth member of the DirtyFrag family of Linux kernel local privilege escalation vulnerabilities. Each member shares the same root failure: file-backed page-cache memory is exposed to network packet operations, and…

    Patched 2026-06-28
  • CVE-2026-50656 binary HIGH 7.8 EPSS 11%

    CVE-2026-50656 RoguePlanet — Safe Vulnerability Checker (Resurface)

    CVE-2026-50656 is a High-severity Elevation of Privilege vulnerability in the Microsoft Malware Protection Engine, publicly referred to as RoguePlanet. It stems from improper link resolution before file access (CWE-59) — the engine follows attacker-controlled…

    Patched 2026-06-26
  • CVE-2026-50656 binary HIGH 7.8 EPSS 11%

    RoguePlanet — Windows Defender LPE via ISO Mount + Task Scheduler Race Condition

    RoguePlanet is a local privilege escalation exploit for Windows 10 and 11 that abuses a race condition in Windows Defender's scan pipeline. The exploit mounts an attacker-controlled ISO image via the VirtualDisk API, plants an EICAR-like trigger file inside…

    Unpatched 2026-06-10
  • CVE-2026-46333 binary HIGH

    ssh-keysign-pwn: pidfd_getfd FD Theft via mm-NULL Exit Window (CVE-2026-46333)

    ssh-keysign-pwn demonstrates a local file-descriptor theft primitive on vulnerable Linux kernels. During process exit, a race window appears after exitmm() but before file descriptors are closed; in that state pidfdgetfd(2) can bypass expected dumpable checks…

    Patched 2026-06-05
  • CVE-2026-48770, CVE-2026-48778, CVE-2026-48800 binary HIGH 5

    Notepad++ <= 8.9.6 Multiple Vulnerabilities (CVE-2026-48770, CVE-2026-48778, CVE-2026-48800)

    This PoC set covers three Notepad++ vulnerabilities affecting versions up to 8.9.6. CVE-2026-48770 demonstrates an out-of-bounds read crash by sending malformed WMCOPYDATA data to a running Notepad++ process. CVE-2026-48778 and CVE-2026-48800 demonstrate…

    Patched 2026-05-28
  • binary HIGH

    PinTheft: RDS Double-Free → LPE

    PinTheft is a Linux local privilege escalation exploit targeting a double-free in the RDS zerocopy send path (rdsmessagezcopyfromuser()). When a multi-page zerocopy send faults on a later page, the error path drops already-pinned pages, but RDS message…

    Unverified 2026-05-20
  • N/A binary HIGH

    DirtyDecrypt / DirtyCBC — rxgk Page-Cache Write (Dirty Pipe Variant)

    DirtyDecrypt (also called DirtyCBC) is a variant of the CopyFail / DirtyFrag / Fragnesia bug class. rxgkdecryptskb() in net/rxrpc/rxgkcommon.h calls skbtosgvec() followed by cryptokrb5decrypt() without first calling skbcowdata(). The krb5enc AEAD template…

    Unverified 2026-05-18
  • CVE-2025-24054 binary MEDIUM 6.5 KEV EPSS 59%

    Windows NTLM Hash Disclosure via File Explorer - CVE-2025-24054

    CVE-2025-24054 is a zero-click NTLMv2-SSP hash disclosure vulnerability in Windows File Explorer. When a user opens a ZIP archive containing a crafted .searchConnector-ms file, Windows Explorer automatically resolves an embedded UNC path during file preview,…

    Unverified 2026-05-17
  • CVE-2025-26633 binary HIGH KEV Ransomware EPSS 30%

    Windows MMC MSC EvilTwin - CVE-2025-26633

    CVE-2025-26633 is a zero-day vulnerability in Microsoft Management Console (MMC) that was exploited in the wild by Russian APT group Water Gamayun (EncryptHub/Larva-208). An attacker crafts a malicious .msc file that abuses the MUIPath resolution mechanism:…

    Unverified 2026-05-17
  • CVE-2025-62215 binary HIGH 7 KEV

    Windows Kernel Elevation of Privilege - Race Condition / Double-Free (CVE-2025-62215)

    CVE-2025-62215 is a Windows Kernel Elevation of Privilege vulnerability disclosed and patched in November 2025, confirmed to have been actively exploited as a zero-day in the wild prior to patching. The bug combines a race condition in kernel resource…

    Patched 2026-05-17
  • CVE-2025-21756 binary HIGH 7.8

    Linux vsock Use-After-Free VM Escape (CVE-2025-21756)

    CVE-2025-21756 is a use-after-free vulnerability in the Linux kernel's vsock (virtual socket) subsystem. An attacker with code execution inside a virtual machine can exploit this bug to escape the VM boundary and gain root-level code execution on the…

    Patched 2026-05-17
  • CVE-2024-1086 binary HIGH 7.8 KEV Ransomware EPSS 28%

    Linux nf_tables Use-After-Free Local Privilege Escalation (CVE-2024-1086)

    CVE-2024-1086 is a use-after-free vulnerability in the Linux kernel's netfilter nftables subsystem that allows an unprivileged local user to escalate privileges to root. The exploit achieves a 99.4% success rate on KernelCTF images and works universally…

    Patched 2026-05-17
  • CVE-2026-31431 binary HIGH KEV EPSS 100%

    Copy Fail Linux Kernel Local Privilege Escalation (CVE-2026-31431)

    Copy Fail (CVE-2026-31431) is a Linux kernel local privilege-escalation vulnerability published by Theori (Xint Code). The provided PoC abuses AFALG AEAD socket operations with crafted parameters and splice() writes to patch privileged executable bytes and…

    Patched 2026-05-17
  • CVE-2025-21298 binary CRITICAL 9.8 EPSS 81%

    Windows OLE Zero-Click RCE via Outlook RTF (CVE-2025-21298)

    CVE-2025-21298 is a critical Windows OLE memory-corruption vulnerability in ole32.dll that can be triggered through malicious RTF content. In Outlook scenarios, preview-pane rendering is sufficient to trigger the vulnerable parsing flow, making this…

    Patched 2026-05-16
  • binary CRITICAL

    QEMUtiny - QEMU CXL Type-3 Memory Corruption Chain

    QEMUtiny is a memory corruption exploit chain in QEMU CXL Type-3 emulation that combines an out-of-bounds read (GETLOG) with an out-of-bounds write (SETFEATURE). The PoC leaks QEMU process pointers and then corrupts CXL device-adjacent state to steer…

    Unverified 2026-05-16
  • CVE-2026-34621 binary CRITICAL 9.8 KEV

    Adobe Acrobat/Reader Prototype Pollution Sandbox Escape (CVE-2026-34621)

    This repository contains a Python-based exploit generator for CVE-2026-34621, described as a prototype pollution vulnerability in Adobe Acrobat and Reader that can break JavaScript trust boundaries. The generated PDF embeds JavaScript intended to escalate…

    Unverified 2026-05-16
  • CVE-2026-33825 binary HIGH 7.8 KEV Ransomware

    RedSun Privileged File Write (CVE-2026-33825)

    RedSun documents a local privilege-escalation technique where Defender's handling of a cloud-tagged malicious file can be abused as a privileged file write primitive. The PoC orchestrates file operations so the antimalware rewrite path lands on a high-value…

    Patched 2026-05-15
  • CVE-2020-17103 binary HIGH 7.8 EPSS 27%

    MiniPlasma - Windows Cloud Files Mini Filter Driver LPE (CVE-2020-17103)

    MiniPlasma is a fully weaponized Windows LPE that exploits a race condition in cldflrt!HsmOsBlockPlaceholderAccess inside cldflt.sys — the same vulnerability originally discovered by James Forshaw (Google Project Zero) and reported as CVE-2020-17103 in 2020.…

    Patched 2026-05-15
  • CVE-2024-21338 binary HIGH 7.8 KEV Ransomware EPSS 60%

    CVE-2024-21338 — Local Privilege Escalation from Admin to Kernel

    This PoC targets CVE-2024-21338, a Windows local privilege-escalation issue that enables escalation from local administrator context toward kernel-level control. The exploit chain performs token impersonation and then abuses an AppLocker IOCTL handler with…

    Patched 2026-05-15
  • CVE-2026-33825 binary HIGH 7.8 KEV Ransomware

    BlueHammer Defender Local Privilege Escalation (CVE-2026-33825)

    BlueHammer is a Windows local privilege-escalation PoC targeting Defender-associated update and scanning behavior. The exploit orchestrates object-manager symbolic links, directory change notifications, oplocks, RPC-triggered Defender activity, and…

    Patched 2026-05-15
  • CVE-2026-46300 binary HIGH 7.8

    Linux XFRM ESP-in-TCP Local Privilege Escalation (Fragnesia)

    CVE-2026-46300 ("Fragnesia") is a universal Linux local privilege escalation vulnerability in the XFRM ESP-in-TCP subsystem. It is a member of the Dirty Frag vulnerability class — a separate bug from the original dirtyfrag — that abuses a logic flaw where the…

    Patched 2026-05-14
  • CVE-2026-43500, CVE-2026-43284 binary CRITICAL 7.8 EPSS 93%

    Dirty Frag: Linux XFRM/RxRPC Page Cache Write Chain LPE

    Dirty Frag is a universal Linux Local Privilege Escalation (LPE) vulnerability class discovered by Hyunwoo Kim (@v4bel) that chains two Page Cache Write primitives: the xfrm-ESP Page-Cache Write (CVE-2026-43284) and the RxRPC Page-Cache Write…

    Patched 2026-05-14