PoC Archive PoC Archive

binary PoCs

subscribe (RSS)

Proof-of-concept research filed under the binary category.

Entries

140

in binary

CISA KEV

12

exploited in the wild

Ransomware

5

known campaign use

Unpatched

79

no vendor fix

Critical

32

23% of listed

140 entries

Severity

Exploitation signals

Patch status

Date range

→
Sort

140 result(s)

BINARY LIST 140 shown · 140 indexed
PoC titleSeverity
Linux XFRM nat_keepalive Double-Free LPE (CVE-2026-72137)
CVE-2026-72137 binary Unverified
HIGH 7.8
Linux SCTP Stream Rollback UAF LPE (CVE-2026-52929)
CVE-2026-52929 binary Unverified
HIGH 7.8
Linux SCTP Stale COOKIE-ECHO UAF LPE (CVE-2026-52924)
CVE-2026-52924 binary Unverified
CRITICAL 9.8
Linux SCTP auth_enable Sysctl UAF LPE (CVE-2026-68162)
CVE-2026-68162 binary Unverified
HIGH 7.8
Linux Open vSwitch Tunnel Netdev UAF LPE (CVE-2026-31678)
CVE-2026-31678 binary Unverified
HIGH 7.8
Linux Netfilter nf_queue Bridge Device UAF LPE (CVE-2026-72255)
CVE-2026-72255 binary Unverified
HIGH 7.8
Linux IPVS One-Packet Flag Propagation UAF LPE (CVE-2026-80714)
CVE-2026-80714 binary Unverified
CRITICAL 9.8
Linux IPv6 fib6 Rule Suppression UAF LPE (CVE-2026-74581)
CVE-2026-74581 binary Unverified
HIGH 7.8
Linux io_uring Poll Signed Comparison LPE (CVE-2026-52933)
CVE-2026-52933 binary Unverified
HIGH 7.8
Linux Bridge Fast-Leave Port Deletion UAF LPE (CVE-2026-74480)
CVE-2026-74480 binary Unverified
CRITICAL 9.8
Node.js Permission Model Symlink Escape (CVE-2025-55130)
CVE-2025-55130 binary Unverified
CRITICAL 9.1
Nginx HTTP/3 QUIC Pool Corruption RCE (CVE-2026-42530)
CVE-2026-42530 binary Unverified
HIGH 8.1
Linux Netfilter xt_IDLETIMER UAF LPE (CVE-2026-23274)
CVE-2026-23274 binary Unverified
HIGH 7.8
Linux Netfilter nf_queue UAF LPE (CVE-2026-52912)
CVE-2026-52912 binary Unverified
HIGH 7.8
Linux MPLS Subsystem UAF LPE (CVE-2026-43042)
CVE-2026-43042 binary Unverified
HIGH 7.1
Linux Kernel posix-cpu-timers Use-After-Free LPE (CVE-2026-64560)
CVE-2026-64560 binary Unverified
HIGH 7.8
Linux Kernel IPC msg_msg Use-After-Free LPE (CVE-2026-52923)
CVE-2026-52923 binary Unverified
HIGH 7.8
Linux Kernel eventpoll Use-After-Free LPE (CVE-2026-43074)
CVE-2026-43074 binary Unverified
HIGH 7.8
Linux IPv6 RPL Routing UAF LPE (CVE-2026-43501)
CVE-2026-43501 binary Unverified
CRITICAL 9.8
Firefox SpiderMonkey JIT Type Confusion (CVE-2026-10702)
CVE-2026-10702 binary Unverified
MEDIUM 4.3
Chrome V8 Type Confusion RCE (CVE-2026-5865)
CVE-2026-5865 binary Unverified
HIGH 8.8
Windows Media Player DLL Hijack -- Local Privilege Escalation (CVE-2026-21508)
CVE-2026-21508 binary Patched
HIGH 7.8
Ubuntu Linux Kernel PPPoL2TP Use-After-Free Local Privilege Escalation (CVE-2026-68398)
CVE-2026-68398 binary Patched
HIGH 7.8
Linux nf_tables Catchall Set Element UAF -- Local Privilege Escalation (CVE-2026-23111)
CVE-2026-23111 binary Patched
HIGH 7.8
Linux AF_UNIX GC vs MSG_PEEK Use-After-Free Container Escape (CVE-2026-53361)
CVE-2026-53361 binary Patched
CRITICAL 9.8
Firefox SpiderMonkey JIT Miscompilation and Use-After-Free (CVE-2026-2764)
CVE-2026-2764 / MFSA 2026-13 binary Unverified
HIGH 8.8
Linux Kernel — SCTPhantom: SCTP ASCONF DEL-IP Use-After-Free Local Privilege Escalation (CVE-2026-64564)
CVE-2026-64564 binary Patched
HIGH 7.8
Linux Kernel — qdisc Rate-Table Race Condition Local Privilege Escalation (CVE-2026-68138)
CVE-2026-68138 binary Patched
HIGH 7.8
Linux Kernel — OVSwrap: Open vSwitch Conntrack Local Privilege Escalation (CVE-2026-64531)
CVE-2026-64531 binary Patched
HIGH 7.8
Docker — CopyEscape: Container-to-Host Escape via docker cp Race Condition (CVE-2026-17106)
CVE-2026-17106 binary Unverified
CRITICAL 9.8
Windows Defender — ShieldBreak: RoguePlanet (CVE-2026-50656) Patch Bypass via Cloud Files Rehydration + Object Manager Symlinks EPSS 11%
Bypass of CVE-2026-50656 (RoguePlanet); no CVE assigned to ShieldBreak as of 2026-08-11 binary Unpatched
HIGH 7.8
Zapscape — KVM/x86 Shadow-MMU Recursive-Zap Guest-to-Host Escape (CVE-2026-64561)
CVE-2026-64561 binary Patched
HIGH 8.8
MariaDB — Low-Privilege Remote Code Execution via ST_Area OOB Read + SYS_REFCURSOR Use-After-Free
MDEV-40328 (ST_Area OOB read); cursor-array UAF has no assigned CVE yet binary Unpatched
CRITICAL 8.8
Barrier 2.4.0 — barrierd.exe Unauthenticated IPC → SYSTEM Privilege Escalation (NotCVE-2026-0010)
NotCVE-2026-0010 (disputed CVE assignment — author contests the identifier) binary Unverified
HIGH
Windows WalletService Known-Folder Redirection → ESE Persisted-Callback DLL Load Local Privilege Escalation (CVE-2026-49176)
CVE-2026-49176 binary Patched
HIGH 7.8
ITScape — KVM/arm64 vGIC-ITS Guest-to-Host VM Escape (CVE-2026-46316)
CVE-2026-46316 (GHSA-qcxh-2cm7-9fcc) binary Patched
CRITICAL 9.3
GreatXML — WinRE / Defender Offline-Scan Trust-Boundary Abuse → BitLocker Bypass (No CVE)
N/A (no CVE assigned, no Microsoft advisory as of 2026-07-27) binary Unpatched
HIGH
V8 Array Iterator Maglev Type Confusion — addrof/fakeobj Primitives (CVE-2026-14431)
CVE-2026-14431 binary Unpatched
HIGH 8.8
LegacyHive - Windows user profile service arbitrary hive load elevation of privileges vulnerability
binary Patched
HIGH
Linux Kernel rtmutex Priority-Inheritance Stack-UAF — "GhostLock" (CVE-2026-43499, Nebula Security weaponized variant)
CVE-2026-43499 (aka "GhostLock") binary Patched
HIGH 7.8
Sudo `chroot` Option Local Privilege Escalation (CVE-2025-32463) KEV EPSS 59%
CVE-2025-32463 binary Patched
CRITICAL 9.3
RediShell: Redis Lua Scripting Use-After-Free Leading to JOP-Chained Remote Code Execution (CVE-2025-49844) EPSS 87%
CVE-2025-49844 binary Patched
CRITICAL 9.9
Dolby Unified (DDPlus) Decoder Out-of-Bounds Write via Evolution Data (CVE-2025-54957)
CVE-2025-54957 binary Unverified
CRITICAL 9.8
XNU PF_ROUTE RTA_GENMASK Heap Buffer Overflow (CVE-2026-20698)
CVE-2026-20698 binary Patched
HIGH
XIGNCODE3 Anti-Cheat Driver PPL-Bypass LSASS Credential Dump (CVE-2026-3609)
CVE-2026-3609 binary Patched
HIGH
Windows Shell LNK _IDCONTROLW Zero-Click SMB Coercion Builder — CVE-2026-32202 KEV EPSS 64%
CVE-2026-32202 (related: CVE-2026-21510) binary Unverified
HIGH
Windows Secure Kernel (VTL1/VSM) Memory Corruption PoC (CVE-2026-26179 / ZDI-26-276)
CVE-2026-26179 / ZDI-26-276 binary Unverified
HIGH
Windows Push Notification Service Use-After-Free Race (CVE-2026-42978)
CVE-2026-42978 binary Unverified
HIGH 7.8
Windows pstrip64.sys BYOVD Physical Memory Local Privilege Escalation — CVE-2026-29923
CVE-2026-29923 binary Unverified
CRITICAL
Windows Kernel Local Privilege Escalation via SeDebugPrivilege Bit Corruption (CVE-2026-40369)
CVE-2026-40369 binary Unverified
HIGH
Windows HTTP.sys Header-Count-Triggered Kernel Memory Corruption / BSOD (CVE-2026-49160) EPSS 54%
CVE-2026-49160 binary Patched
HIGH
Windows Error Reporting Service ALPC Local Privilege Escalation (CVE-2026-20817)
CVE-2026-20817 binary Unverified
HIGH
Windows CLFS.sys Unrecoverable State / BSoD via ReadFile on Log File Handle (CVE-2026-2636)
CVE-2026-2636 binary Patched
MEDIUM
VirtualBox DevVGA_VBVA Integer Overflow leading to Guest-Triggerable DoS (CVE-2026-35250)
CVE-2026-35250 binary Unverified
LOW 2.3
Vim Modeline `path` Option Backtick-Expansion Command Injection (CVE-2026-44656)
CVE-2026-44656 binary Patched
HIGH
V8 JavaScript Engine Exploit — "Longinus" Kit (CVE-2026-6307)
CVE-2026-6307 binary Unverified
CRITICAL
snapd snap-confine / systemd-tmpfiles Race Condition LPE (CVE-2026-3888)
CVE-2026-3888 binary Patched
HIGH
Samsung SveService Native Out-of-Bounds Write (CVE-2026-21018)
CVE-2026-21018 (Samsung SVE-2026-0478, SMR May 2026) binary Unverified
HIGH
Samsung Android AT-Command Filter Bypass to system_server Code Execution (CVE-2026-20980)
CVE-2026-20980 (chained with CVE-2026-20981 and CVE-2026-20982) binary Unverified
CRITICAL
rldns 1.3 Heap-Based Out-of-Bounds Read Remote DoS (CVE-2026-27831)
CVE-2026-27831 binary Patched
MEDIUM
PostgreSQL pgcrypto PGP Heap Overflow to Superuser Escalation — CVE-2026-2005
CVE-2026-2005 binary Unverified
CRITICAL
Portwell Engineering Toolkits Driver Arbitrary Physical Memory R/W LPE (CVE-2026-3437)
CVE-2026-3437 binary Unverified
HIGH
PinTheft: RDS zcopy Refcount-Steal Double-Free LPE — Pure NASM Rewrite (CVE-2026-43494)
CVE-2026-43494 binary Patched
HIGH
Pardus Software Center Local Privilege Escalation via APT Option Injection (CVE-2026-14459 / CVE-2026-14460)
CVE-2026-14459 (also covers CVE-2026-14460) binary Patched
HIGH 8.8
PackageKit TOCTOU Local Privilege Escalation (CVE-2026-41651)
CVE-2026-41651 binary Patched
HIGH
Oracle VirtualBox Shared Folders Kernel Memory Exhaustion DoS (CVE-2026-21986)
CVE-2026-21986 binary Patched
MEDIUM 7.1
OP-TEE PKCS#11 TA Out-of-Bounds Heap Write via `C_GetAttributeValue` (CVE-2026-33317)
CVE-2026-33317 (GHSA-8cqw-mg7v-c9p9) binary Patched
HIGH 8.7
Notepad++ nativeLang.xml Format String Crash / Info Disclosure — CVE-2026-3008
CVE-2026-3008 binary Unverified
MEDIUM
MIPS-Based Managed Switch Firmware Pre-Auth Kernel RCE — CVE-2026-1668
CVE-2026-1668 binary Unverified
CRITICAL
MiniTool pwdrvio.sys Kernel Write-What-Where — Local Privilege Escalation Primitive (CVE-2026-36981)
CVE-2026-36981 binary Patched
HIGH
MiniTool pwdrvio.sys Kernel Driver Buffer Overflow — Local DoS/BSOD (CVE-2026-36980)
CVE-2026-36980 binary Patched
MEDIUM
Microsoft Defender Link Following Local Privilege Escalation (CVE-2026-41091) KEV
CVE-2026-41091 binary Unpatched
HIGH 7.8
MariaDB JSON_SCHEMA_VALID() Heap Overflow — Privilege Escalation to UDF RCE (CVE-2026-32710)
CVE-2026-32710 binary Patched
CRITICAL
Linux Kernel PPP Unprivileged User-Namespace Precondition Probe — CVE-2026-53075
CVE-2026-53075 binary Patched
INFO
Linux Kernel mm/mseal VMA-Merge Stale-Bound Bug (CVE-2026-23416)
CVE-2026-23416 binary Patched
MEDIUM
Linux Kernel KFENCE Cross-Cache Free of SKB Head via bpf_prog_test_run_skb — CVE-2026-31429
CVE-2026-31429 binary Patched
MEDIUM
Linux Kernel Futex-PI rtmutex remove_waiter() Use-After-Free (CVE-2026-43499)
CVE-2026-43499 binary Patched
HIGH 7.8
Linux FUSE Readdir Cache Out-of-Bounds Write to Root LPE — CVE-2026-31694
CVE-2026-31694 binary Patched
HIGH
Linux BPF Verifier Scalar-Forking Soundness Bug to Container Escape — CVE-2026-31413
CVE-2026-31413 binary Patched
CRITICAL
LibRaw pana8.cpp GetDBit() Out-of-Bounds Array Read (CVE-2026-36834)
CVE-2026-36834 binary Unverified
MEDIUM 6.5
libopenapv / Android APV Codec Zero-Click Heap Buffer Overflow (CVE-2026-0006)
CVE-2026-0006 binary Unverified
CRITICAL 9.8
Lenovo LDE (LdeApi.Server.exe) Unimpersonated Junction-Based Arbitrary File Write to SYSTEM (CVE-2026-0827)
CVE-2026-0827 (Lenovo advisory LEN-210693) binary Unverified
HIGH
KVM SEV-SNP Page State Change (PSC) Heap Out-of-Bounds — CVE-2026-53360
CVE-2026-53360 binary Patched
HIGH
KillChain — Vulnerable Kernel Driver IOCTL Protected-Process Termination (CVE-2026-0828)
CVE-2026-0828 binary Unverified
HIGH
GNU inetutils telnetd Local Privilege Escalation via NEW-ENVIRON Injection — CVE-2026-28372
CVE-2026-28372 binary Patched
HIGH 7.4
gdk-pixbuf JPEG Loader Heap Buffer Overflow — CVE-2026-5201
CVE-2026-5201 binary Patched
HIGH 7.5
FreeBSD setcred(2) Kernel Stack Buffer Overflow — Local Privilege Escalation (CVE-2026-45250)
CVE-2026-45250 binary Unverified
CRITICAL
FreeBSD OSS /dev/dsp Stale Kernel-Stack Buffer Local Privilege Escalation (CVE-2026-49417)
CVE-2026-49417 binary Unverified
HIGH
FreeBSD Linuxulator AT_SECURE=0 Local Privilege Escalation via LD_PRELOAD (CVE-2026-49413)
CVE-2026-49413 binary Unverified
HIGH
FreeBSD exec_args_adjust_args() Out-of-Bounds memmove — Local Privilege Escalation via sshd Race (CVE-2026-7270)
CVE-2026-7270 binary Unverified
CRITICAL
FreeBSD /dev/dsp (OSS) Negative-Offset mmap Kernel Memory Corruption LPE (CVE-2026-45258)
CVE-2026-45258 binary Unverified
CRITICAL
Fortinet FortiClientLinux VPN Config Symlink/Shared-Object Loading LPE — CVE-2026-24018
CVE-2026-24018 binary Unverified
HIGH
Firefox/Tor Browser IndexedDB Ordering Fingerprint — CVE-2026-6770
CVE-2026-6770 binary Unverified
MEDIUM
ExifTool Metadata Field Command Injection (macOS) — CVE-2026-3102
CVE-2026-3102 binary Patched
HIGH
Discord Desktop Client Uncontrolled Search Path Element / Local Code Execution (CVE-2026-0776)
CVE-2026-0776 (ZDI-CAN-27057, credit: Trend Micro Zero Day Initiative) binary Unverified
HIGH 7.3
DirtyDecrypt-Go — RxRPC rxgk Page-Cache Overwrite LPE (Go Port) — CVE-2026-31635
CVE-2026-31635 binary Patched
HIGH
Balena Etcher Windows TOCTOU Privilege Escalation — CVE-2026-30332
CVE-2026-30332 binary Unverified
HIGH
ASUSTOR ADM vpnupload.cgi Format String / Stack Buffer Overflow RCE — CVE-2026-6643
CVE-2026-6643 binary Unverified
CRITICAL
ASUS DriverHub Update TOCTOU Local Privilege Escalation — CVE-2026-1880
CVE-2026-1880 binary Patched
MEDIUM
AppleSEPKeyStore IOKit Use-After-Free (CVE-2026-20637)
CVE-2026-20637 binary Patched
HIGH
AppleM2ScalerCSCDriver Shared Scheduler Use-After-Free (CVE-2026-43655)
CVE-2026-43655 binary Unverified
HIGH
AppleJPEGDriver startDecoder Timeout Use-After-Free (CVE-2026-20687)
CVE-2026-20687 binary Patched
HIGH
Android ActivityManagerService dumpBitmapsProto() Missing Permission Check (CVE-2026-0047)
CVE-2026-0047 binary Unpatched
CRITICAL 8.4
VLC Bundled FFmpeg VP9 Decoder Resolution-Change Heap Crash
None assigned as of 2026-07-03 binary Unverified
MEDIUM
System Informer phsvc Trusted-Host Confused Deputy LPE
None assigned as of 2026-07-03 binary Unverified
HIGH
QEMU CXL Type-3 Mailbox Guest-to-Host Escape
None assigned as of 2026-07-03 binary Unverified
CRITICAL
Pillow ImageCms Mutable output_mode Heap OOB Write
None assigned as of 2026-07-03 binary Unverified
HIGH
objdump DLX ELF Backend Out-of-Bounds Write (Crash-to-Calc)
None assigned as of 2026-07-03 binary Unverified
MEDIUM
Lunar Client Modrinth Explore Raw-HTML to Local Launcher Execution Chain
None assigned as of 2026-07-03 binary Unverified
CRITICAL 3.1
libarchive ZIP Declared-Size Boundary Bypass via debuginfod
None assigned as of 2026-07-03 binary Unverified
MEDIUM
ImageMagick Ghostscript Delegate Search Path Hijack
None assigned as of 2026-07-03 binary Unverified
HIGH
Ghidra 12.1.2 Conditional Swift Demangler ACE (plus TraceRMI RCE and SevenZipJBinding Reachability)
None assigned as of 2026-07-03 binary Unverified
MEDIUM
FFmpeg RASC Decoder DLTA Heap Out-of-Bounds Write
None assigned as of 2026-07-03 binary Unpatched
CRITICAL
AnyDesk Printer Pipe COM Impersonation Local Privilege Escalation
None assigned as of 2026-07-03 binary Unverified
HIGH
Linux Kernel act_pedit Partial COW Page-Cache LPE (CVE-2026-46331)
CVE-2026-46331 binary Patched
HIGH 7.8
FFmpeg MagicYUV Decoder Out-of-Bounds Write / RCE — PixelSmash (CVE-2026-8461)
CVE-2026-8461 binary Patched
HIGH 8.8
Claude Desktop Cowork VM Image Integrity Bypass / Local Persistence (CVE-2026-7574)
CVE-2026-7574 binary Unverified
HIGH 8.7
Windows CTFMON Arbitrary Section Object EoP — GreenPlasma (CVE-2026-45586)
CVE-2026-45586 binary Patched
HIGH 7.8
DirtyClone — Linux Kernel LPE via Cloned Packet Page-Cache Overwrite (CVE-2026-43503)
CVE-2026-43503 binary Patched
HIGH 8.8
CVE-2026-50656 RoguePlanet — Safe Vulnerability Checker (Resurface) EPSS 11%
CVE-2026-50656 binary Patched
HIGH 7.8
RoguePlanet — Windows Defender LPE via ISO Mount + Task Scheduler Race Condition EPSS 11%
CVE-2026-50656 binary Unpatched
HIGH 7.8
ssh-keysign-pwn: pidfd_getfd FD Theft via mm-NULL Exit Window (CVE-2026-46333)
CVE-2026-46333 binary Patched
HIGH
Notepad++ <= 8.9.6 Multiple Vulnerabilities (CVE-2026-48770, CVE-2026-48778, CVE-2026-48800)
CVE-2026-48770, CVE-2026-48778, CVE-2026-48800 binary Patched
HIGH 5
PinTheft: RDS Double-Free → LPE
binary Unverified
HIGH
DirtyDecrypt / DirtyCBC — rxgk Page-Cache Write (Dirty Pipe Variant)
N/A (reported as duplicate by kernel maintainers; patched on mainline) binary Unverified
HIGH
Windows NTLM Hash Disclosure via File Explorer - CVE-2025-24054 KEV EPSS 59%
CVE-2025-24054 binary Unverified
MEDIUM 6.5
Windows MMC MSC EvilTwin - CVE-2025-26633 KEV RW EPSS 30%
CVE-2025-26633 binary Unverified
HIGH
Windows Kernel Elevation of Privilege - Race Condition / Double-Free (CVE-2025-62215) KEV
CVE-2025-62215 binary Patched
HIGH 7
Linux vsock Use-After-Free VM Escape (CVE-2025-21756)
CVE-2025-21756 binary Patched
HIGH 7.8
Linux nf_tables Use-After-Free Local Privilege Escalation (CVE-2024-1086) KEV RW EPSS 28%
CVE-2024-1086 binary Patched
HIGH 7.8
Copy Fail Linux Kernel Local Privilege Escalation (CVE-2026-31431) KEV EPSS 100%
CVE-2026-31431 binary Patched
HIGH
Windows OLE Zero-Click RCE via Outlook RTF (CVE-2025-21298) EPSS 81%
CVE-2025-21298 binary Patched
CRITICAL 9.8
QEMUtiny - QEMU CXL Type-3 Memory Corruption Chain
binary Unverified
CRITICAL
Adobe Acrobat/Reader Prototype Pollution Sandbox Escape (CVE-2026-34621) KEV
CVE-2026-34621 binary Unverified
CRITICAL 9.8
RedSun Privileged File Write (CVE-2026-33825) KEV RW
CVE-2026-33825 binary Patched
HIGH 7.8
MiniPlasma - Windows Cloud Files Mini Filter Driver LPE (CVE-2020-17103) EPSS 27%
CVE-2020-17103 binary Patched
HIGH 7.8
CVE-2024-21338 — Local Privilege Escalation from Admin to Kernel KEV RW EPSS 60%
CVE-2024-21338 binary Patched
HIGH 7.8
BlueHammer Defender Local Privilege Escalation (CVE-2026-33825) KEV RW
CVE-2026-33825 binary Patched
HIGH 7.8
Linux XFRM ESP-in-TCP Local Privilege Escalation (Fragnesia)
CVE-2026-46300 binary Patched
HIGH 7.8
Dirty Frag: Linux XFRM/RxRPC Page Cache Write Chain LPE EPSS 93%
CVE-2026-43500, CVE-2026-43284 binary Patched
CRITICAL 7.8