PoC Archive PoC Archive

tag

Privilege-Escalation

Windows Media Player DLL Hijack -- Local Privilege Escalation (CVE-2026-21508)
CVE-2026-21508 binary Patched
CVE-2026-21508binaryHIGH 7.8Patched2026-08-16Ubuntu Linux Kernel PPPoL2TP Use-After-Free Local Privilege Escalation (CVE-2026-68398)
CVE-2026-68398 binary Patched
CVE-2026-68398binaryHIGH 7.8Patched2026-08-16Linux nf_tables Catchall Set Element UAF -- Local Privilege Escalation (CVE-2026-23111)
CVE-2026-23111 binary Patched
CVE-2026-23111binaryHIGH 7.8Patched2026-08-16Windows Kerberos — ResetNightmare: Arbitrary Password Reset via Change Password Protocol Validation Flaw (CVE-2026-27912)
CVE-2026-27912 network Unverified
CVE-2026-27912networkHIGH 8Unverified2026-08-11Windows Defender — ShieldBreak: RoguePlanet (CVE-2026-50656) Patch Bypass via Cloud Files Rehydration + Object Manager Symlinks EPSS 11%
Bypass of CVE-2026-50656 (RoguePlanet); no CVE assigned to ShieldBreak as of 2026-08-11 binary Unpatched
Bypass of CVE-2026-50656binaryHIGH 7.8Unpatched2026-08-11Active Directory — SPN Unicode Collision Detection Scanner (CVE-2026-25177)
CVE-2026-25177 network Patched
CVE-2026-25177networkHIGH 8.8Patched2026-08-11Check Point Security Management / Multi-Domain Server SmartConsole Authentication Bypass via Forged Application Certificate Bind (CVE-2026-16232) KEV EPSS 72%
CVE-2026-16232 network Patched
CVE-2026-16232networkCRITICAL 9.1Patched2026-08-09Barrier 2.4.0 — barrierd.exe Unauthenticated IPC → SYSTEM Privilege Escalation (NotCVE-2026-0010)
NotCVE-2026-0010 (disputed CVE assignment — author contests the identifier) binary Unverified
NotCVE-2026-0010binaryHIGHUnverified2026-08-01Windows WalletService Known-Folder Redirection → ESE Persisted-Callback DLL Load Local Privilege Escalation (CVE-2026-49176)
CVE-2026-49176 binary Patched
CVE-2026-49176binaryHIGH 7.8Patched2026-07-27AD CS/AD FS Enrollment "cdc" Chase Attribute Abuse → Domain Controller Impersonation (CertiGhost, CVE-2026-54121)
CVE-2026-54121 network Patched
CVE-2026-54121networkHIGH 8.8Patched2026-07-27wp2shell — WordPress Core Pre-Auth SQLi → Row Forgery → Admin Creation → RCE (CVE-2026-63030 + CVE-2026-60137) KEV EPSS 97%
CVE-2026-63030 (REST /batch/v1 route confusion, CVSS 7.5), CVE-2026-60137 (author__not_in SQL injection, CVSS 9.1); GHSA-ff9f-jf42-662q, GHSA-fpp7-x2x2-2mjf web Patched
CVE-2026-63030webCRITICAL 9.1Patched2026-07-19Cisco Unified Communications Manager WebDialer SSRF → Arbitrary File Write → Root (CVE-2026-20230) KEV EPSS 88%
CVE-2026-20230 (cisco-sa-cucm-ssrf-cXPnHcW) network Patched
CVE-2026-20230networkCRITICAL 8.6Patched2026-07-19Flowise Enterprise Authentication Bypass via Hardcoded Default JWT Secrets (CVE-2026-56271)
CVE-2026-56271 (GHSA-cc4f-hjpj-g9p8) web Patched
CVE-2026-56271webCRITICAL 9.8Patched2026-07-12WordPress Service Finder Bookings ≤ 6.0 Authentication Bypass via `original_user_id` Cookie (CVE-2025-5947)
CVE-2025-5947 web Unverified
CVE-2025-5947webCRITICAL 9.8Unverified2026-07-06WordPress Mobile Builder Plugin JWT Authentication Bypass to Admin Account Creation (CVE-2025-68860)
CVE-2025-68860 web Unpatched
CVE-2025-68860webCRITICAL 9.8Unpatched2026-07-06TNC Toolbox: Web Performance Unauthenticated cPanel Credential Exposure (CVE-2025-12539)
CVE-2025-12539 web Patched
CVE-2025-12539webCRITICAL 10Patched2026-07-06Sudo `chroot` Option Local Privilege Escalation (CVE-2025-32463) KEV EPSS 59%
CVE-2025-32463 binary Patched
CVE-2025-32463binaryCRITICAL 9.3Patched2026-07-06Sneeit Framework <= 8.3 Unauthenticated RCE via `call_user_func()` — Rogue Admin Creation (CVE-2025-6389) EPSS 76%
CVE-2025-6389 web Unverified
CVE-2025-6389webCRITICAL 9.8Unverified2026-07-06Simple User Registration WordPress Plugin — Unauthenticated Privilege Escalation (CVE-2025-4334)
CVE-2025-4334 web Unverified
CVE-2025-4334webCRITICAL 9.8Unverified2026-07-06Simple Business Directory Pro Unauthenticated Password Reset to Admin Takeover (CVE-2025-53580)
CVE-2025-53580 web Patched
CVE-2025-53580webCRITICAL 9.8Patched2026-07-06Real Spaces WordPress Theme Unauthenticated Privilege Escalation via `imic_agent_register` (CVE-2025-6758)
CVE-2025-6758 web Unverified
CVE-2025-6758webCRITICAL 9.8Unverified2026-07-06Opal Estate Pro WordPress Plugin Unauthenticated Administrator Registration (CVE-2025-6934) EPSS 25%
CVE-2025-6934 web Unverified
CVE-2025-6934webCRITICAL 9.8Unverified2026-07-06Grafana Enterprise SCIM User ID Collision / Impersonation (CVE-2025-41115) EPSS 19%
CVE-2025-41115 web Patched
CVE-2025-41115webCRITICAL 10Patched2026-07-06Frontend Admin by DynamiApps — Unauthenticated Administrator Account Creation (CVE-2025-13342)
CVE-2025-13342 web Patched
CVE-2025-13342webCRITICAL 9.8Patched2026-07-06Fox LMS `createOrder` Unauthenticated Privilege Escalation to Administrator (CVE-2025-14156)
CVE-2025-14156 web Unverified
CVE-2025-14156webCRITICAL 9.8Unverified2026-07-06ConnectWise Automate Adversary-in-the-Middle Remote Code Execution (CVE-2025-11492)
CVE-2025-11492 network Patched
CVE-2025-11492networkCRITICAL 9.6Patched2026-07-06AI Engine WordPress Plugin Unauthenticated MCP Token Disclosure to Admin Account Creation (CVE-2025-11749) EPSS 75%
CVE-2025-11749 web Unverified
CVE-2025-11749webCRITICAL 9.8Unverified2026-07-06ACF Extended (ACFE) `prepare_form()` Unauthenticated RCE via Privilege Escalation (CVE-2025-13486) EPSS 68%
CVE-2025-13486 web Unverified
CVE-2025-13486webCRITICAL 9.8Unverified2026-07-06YayMail WooCommerce Plugin Missing Authorization to Privilege Escalation — CVE-2026-1937
CVE-2026-1937 web Unverified
CVE-2026-1937webHIGH 7.2Unverified2026-07-05WP Captcha PRO Subscriber-to-Administrator Authentication Bypass — CVE-2026-5415
CVE-2026-5415 web Unverified
CVE-2026-5415webHIGH 8.8Unverified2026-07-05WordPress "Import and Export Users and Customers" Plugin Privilege Escalation (CVE-2026-3629)
CVE-2026-3629 web Unverified
CVE-2026-3629webCRITICALUnverified2026-07-05WooCommerce Wholesale Lead Capture — Unauthenticated Privilege Escalation & File Upload RCE (CVE-2026-27542 / CVE-2026-27540)
CVE-2026-27542 (bundled with CVE-2026-27540) web Unverified
CVE-2026-27542webCRITICAL 9.8Unverified2026-07-05WooCommerce Frontend Registration Form Unauthenticated Admin Role Assignment — CVE-2026-54807
CVE-2026-54807 web Unverified
CVE-2026-54807webINFOUnverified2026-07-05Windows Push Notification Service Use-After-Free Race (CVE-2026-42978)
CVE-2026-42978 binary Unverified
CVE-2026-42978binaryHIGH 7.8Unverified2026-07-05Windows Kernel Local Privilege Escalation via SeDebugPrivilege Bit Corruption (CVE-2026-40369)
CVE-2026-40369 binary Unverified
CVE-2026-40369binaryHIGHUnverified2026-07-05Windows Kerberos Reflection via Unicode SPN Normalization Bypass (CVE-2026-26128)
CVE-2026-26128 network Unverified
CVE-2026-26128networkCRITICALUnverified2026-07-05Windows Error Reporting Service ALPC Local Privilege Escalation (CVE-2026-20817)
CVE-2026-20817 binary Unverified
CVE-2026-20817binaryHIGHUnverified2026-07-05Veno File Manager 4.4.9 — Arbitrary File Rename to Privilege Escalation (CVE-2026-37071)
CVE-2026-37071 web Unverified
CVE-2026-37071webHIGHUnverified2026-07-05User Registration & Membership Unauthenticated Admin Privilege Escalation (CVE-2026-1492) EPSS 24%
CVE-2026-1492 web Unverified
CVE-2026-1492webCRITICAL 9.8Unverified2026-07-05TP-Link Tapo C260 Unauthenticated-to-Root RCE Chain — CVE-2026-0651
CVE-2026-0651 (chained with CVE-2026-0652, CVE-2026-0653) network Unverified
CVE-2026-0651networkCRITICALUnverified2026-07-05SonicWall SMA 8200v Cross-Parameter Blind SQL Injection to Root (CVE-2026-4112)
CVE-2026-4112 (SonicWall Advisory SNWLID-2026-0003) network Unverified
CVE-2026-4112networkHIGH 7.2Unverified2026-07-05Samsung Android AT-Command Filter Bypass to system_server Code Execution (CVE-2026-20980)
CVE-2026-20980 (chained with CVE-2026-20981 and CVE-2026-20982) binary Unverified
CVE-2026-20980binaryCRITICALUnverified2026-07-05samlify SAML AttributeValue XML Injection → Privilege Escalation (CVE-2026-46490)
CVE-2026-46490 / GHSA-34r5-q4jw-r36m web Patched
CVE-2026-46490 / GHSA-34r5-q4jw-r36mwebHIGH 8.8Patched2026-07-05Rocket.Chat OAuth2 NoSQL Injection Privilege Escalation — CVE-2026-29198
CVE-2026-29198 web Patched
CVE-2026-29198webCRITICALPatched2026-07-05PostgreSQL pgcrypto PGP Heap Overflow to Superuser Escalation — CVE-2026-2005
CVE-2026-2005 binary Unverified
CVE-2026-2005binaryCRITICALUnverified2026-07-05Portwell Engineering Toolkits Driver Arbitrary Physical Memory R/W LPE (CVE-2026-3437)
CVE-2026-3437 binary Unverified
CVE-2026-3437binaryHIGHUnverified2026-07-05Percona PMM Authenticated RCE via PostgreSQL COPY TO PROGRAM (CVE-2026-25212)
CVE-2026-25212 web Patched
CVE-2026-25212webCRITICAL 9.9Patched2026-07-05Pardus Software Center Local Privilege Escalation via APT Option Injection (CVE-2026-14459 / CVE-2026-14460)
CVE-2026-14459 (also covers CVE-2026-14460) binary Patched
CVE-2026-14459binaryHIGH 8.8Patched2026-07-05PackageKit TOCTOU Local Privilege Escalation (CVE-2026-41651)
CVE-2026-41651 binary Patched
CVE-2026-41651binaryHIGHPatched2026-07-05pac4j JWT Authentication Bypass via Unsigned Token in JWE Wrapper — CVE-2026-29000
CVE-2026-29000 web Patched
CVE-2026-29000webCRITICAL 9.8Patched2026-07-05Nezha Dashboard Path Traversal → JWT Secret Leak → Token Forgery — CVE-2026-53519
CVE-2026-53519 (GHSA-5c25-7vpj-9mqh) web Patched
CVE-2026-53519webINFOPatched2026-07-05Microsoft Defender Link Following Local Privilege Escalation (CVE-2026-41091) KEV
CVE-2026-41091 binary Unpatched
CVE-2026-41091binaryHIGH 7.8Unpatched2026-07-05Masteriyo LMS Authenticated Privilege Escalation to Administrator (CVE-2026-4484)
CVE-2026-4484 web Unverified
CVE-2026-4484webHIGH 8.8Unverified2026-07-05MariaDB JSON_SCHEMA_VALID() Heap Overflow — Privilege Escalation to UDF RCE (CVE-2026-32710)
CVE-2026-32710 binary Patched
CVE-2026-32710binaryCRITICALPatched2026-07-05LiteSpeed cPanel/WHM Plugin Symlink Privilege Escalation — CVE-2026-54420 KEV
CVE-2026-54420 network Unverified
CVE-2026-54420networkHIGH 8.5Unverified2026-07-05LiteLLM Proxy Privilege Escalation via `/user/update` (CVE-2026-47102)
CVE-2026-47102 web Patched
CVE-2026-47102webHIGH 8.8Patched2026-07-05Lenovo LDE (LdeApi.Server.exe) Unimpersonated Junction-Based Arbitrary File Write to SYSTEM (CVE-2026-0827)
CVE-2026-0827 (Lenovo advisory LEN-210693) binary Unverified
CVE-2026-0827binaryHIGHUnverified2026-07-05LatePoint Calendar Booking Plugin Contributor-to-Administrator Privilege Escalation (CVE-2026-49083)
CVE-2026-49083 web Unverified
CVE-2026-49083webHIGH 8.8Unverified2026-07-05LatePoint Calendar Booking Plugin Agent-to-Administrator Privilege Escalation — CVE-2026-6741
CVE-2026-6741 web Patched
CVE-2026-6741webHIGH 8.8Patched2026-07-05LA-Studio Element Kit for Elementor — Unauthenticated Admin Account Creation (CVE-2026-0920)
CVE-2026-0920 web Unverified
CVE-2026-0920webCRITICAL 9.8Unverified2026-07-05Kubernetes `runAsNonRoot` Bypass via UID Integer Overflow (CVE-2026-46680)
CVE-2026-46680 cloud Patched
CVE-2026-46680cloudHIGHPatched2026-07-05KillChain — Vulnerable Kernel Driver IOCTL Protected-Process Termination (CVE-2026-0828)
CVE-2026-0828 binary Unverified
CVE-2026-0828binaryHIGHUnverified2026-07-05Grafana Dashboard Permissions Broken Access Control — Editor-to-Admin Privilege Escalation (CVE-2026-21721)
CVE-2026-21721 web Patched
CVE-2026-21721webHIGHPatched2026-07-05GNU inetutils telnetd Local Privilege Escalation via NEW-ENVIRON Injection — CVE-2026-28372
CVE-2026-28372 binary Patched
CVE-2026-28372binaryHIGH 7.4Patched2026-07-05FreeBSD setcred(2) Kernel Stack Buffer Overflow — Local Privilege Escalation (CVE-2026-45250)
CVE-2026-45250 binary Unverified
CVE-2026-45250binaryCRITICALUnverified2026-07-05FreeBSD /dev/dsp (OSS) Negative-Offset mmap Kernel Memory Corruption LPE (CVE-2026-45258)
CVE-2026-45258 binary Unverified
CVE-2026-45258binaryCRITICALUnverified2026-07-05ElementsKit Elementor Addons Authenticated Stored XSS via REST API (CVE-2026-2600)
CVE-2026-2600 web Patched
CVE-2026-2600webMEDIUM 6.4Patched2026-07-05Easy Elements for Elementor Unauthenticated Privilege Escalation via `custom_meta` Overwrite (CVE-2026-9018)
CVE-2026-9018 web Patched
CVE-2026-9018webHIGH 8.8Patched2026-07-05Divi Form Builder <= 5.1.2 Unauthenticated Privilege Escalation via Role Injection (CVE-2026-5118)
CVE-2026-5118 web Unverified
CVE-2026-5118webCRITICAL 9.8Unverified2026-07-05Branda White Label & Branding Plugin Unauthenticated Account Takeover — CVE-2026-11551
CVE-2026-11551 web Patched
CVE-2026-11551webCRITICAL 9.8Patched2026-07-05Balena Etcher Windows TOCTOU Privilege Escalation — CVE-2026-30332
CVE-2026-30332 binary Unverified
CVE-2026-30332binaryHIGHUnverified2026-07-05Azuriom CMS Broken Access Control — Account Takeover via AzLink Server Token — CVE-2026-54415
CVE-2026-54415 web Patched
CVE-2026-54415webHIGH 3.1Patched2026-07-05Appsmith Table Widget Stored XSS to Admin Account Takeover — CVE-2026-30862
CVE-2026-30862 (GHSA-5hw4-whxv-6794) web Patched
CVE-2026-30862webCRITICAL 9.1Patched2026-07-05Apache NiFi 2.8.0 — EXECUTE_CODE Permission Bypass to Groovy RCE (CVE-2026-39816)
CVE-2026-39816 web Patched
CVE-2026-39816webCRITICALPatched2026-07-05Amazon WorkSpaces Skylight Workspace Config Service Local Privilege Escalation (CVE-2026-7791)
CVE-2026-7791 cloud Unverified
CVE-2026-7791cloudHIGHUnverified2026-07-05Advanced Custom Fields: Extended Unauthenticated Privilege Escalation via `_acf_post_id` Validation Bypass (CVE-2026-8809)
CVE-2026-8809 web Unverified
CVE-2026-8809webCRITICAL 9.8Unverified2026-07-05PostgreSQL Referential-Integrity Owner-Switched Implicit Cast RCE
None assigned as of 2026-07-04 network Unverified
None assigned as of 2026-07-04networkHIGHUnverified2026-07-04MyBB 1.8.40 Limited Admin CP User-Manager to Full Administrator Privilege Escalation
None assigned as of 2026-07-03 (see Notes — CVE-2026-45115 identifies a separate, already-patched MyBB issue) web Unpatched
None assigned as of 2026-07-03webHIGHUnpatched2026-07-03Gogs Admin User Edit CSRF to Git Hook RCE
None assigned as of 2026-07-03 web Unverified
None assigned as of 2026-07-03webCRITICALUnverified2026-07-03Gitea act_runner container.options Host Namespace Escape
None assigned as of 2026-07-03 cloud Unverified
None assigned as of 2026-07-03cloudHIGHUnverified2026-07-03Discourse Scoped API Key Pre-Route Authorization Bypass
None assigned as of 2026-07-03 web Unverified
None assigned as of 2026-07-03webHIGHUnverified2026-07-03AnyDesk Printer Pipe COM Impersonation Local Privilege Escalation
None assigned as of 2026-07-03 binary Unverified
None assigned as of 2026-07-03binaryHIGHUnverified2026-07-03Linux Kernel act_pedit Partial COW Page-Cache LPE (CVE-2026-46331)
CVE-2026-46331 binary Patched
CVE-2026-46331binaryHIGH 7.8Patched2026-06-30DirtyClone — Linux Kernel LPE via Cloned Packet Page-Cache Overwrite (CVE-2026-43503)
CVE-2026-43503 binary Patched
CVE-2026-43503binaryHIGH 8.8Patched2026-06-28Cisco Catalyst SD-WAN Manager Privilege Escalation (CVE-2026-20245) KEV EPSS 25%
CVE-2026-20245 network Unpatched
CVE-2026-20245networkHIGH 7.8Unpatched2026-06-28Azure Networking Privilege Escalation via Missing Privilege Check
CVE-2025-54914 cloud Patched
CVE-2025-54914cloudCRITICAL 10Patched2026-05-17Linux XFRM ESP-in-TCP Local Privilege Escalation (Fragnesia)
CVE-2026-46300 binary Patched
CVE-2026-46300binaryHIGH 7.8Patched2026-05-14