PoC Archive PoC Archive

tag

Reverse-Engineering

  • CVE-2026-18718 misc HIGH 7.5

    Ghidra — Swift Demangler Arbitrary Code Execution via Shared Project Files (CVE-2026-18718)

    Opening someone else's Ghidra project is enough to execute their code — with no prompt, no signature check, and no integrity verification.

    Patched 2026-08-09
  • CVE-2026-40003 hardware HIGH

    ZXIC/Sanechips ZX297520V3 BootROM Arbitrary Memory Write via USB Download Mode (CVE-2026-40003)

    The ZX297520V3 BootROM falls back to a USB download mode when it cannot load or verify a valid image from flash, entering a handshake loop that accepts a stage-1 image over USB for device recovery. The BootROM's image-load command does not validate the…

    Unverified 2026-07-05
  • CVE-2026-32202 binary HIGH KEV EPSS 64%

    Windows Shell LNK _IDCONTROLW Zero-Click SMB Coercion Builder — CVE-2026-32202

    This repository documents a reverse-engineered, undocumented IDCONTROLW structure used internally by shell32.dll to represent Control Panel applet items inside a .lnk file's LinkTargetIDList, based on the researcher's own IDA Pro static analysis and…

    Unverified 2026-07-05
  • None assigned as of 2026-07-03 binary MEDIUM

    Ghidra 12.1.2 Conditional Swift Demangler ACE (plus TraceRMI RCE and SevenZipJBinding Reachability)

    This entry packages three conditional, defensively-scoped findings against Ghidra 12.1.2 rather than a single unconditional exploit. First, the Swift demangler analyzer builds and launches a swift-demangle executable from a program/analyzer-controlled tool…

    Unverified 2026-07-03