PoC Archive PoC Archive

tag

Use-After-Free

Ubuntu Linux Kernel PPPoL2TP Use-After-Free Local Privilege Escalation (CVE-2026-68398)
CVE-2026-68398 binary Patched
CVE-2026-68398binaryHIGH 7.8Patched2026-08-16Linux Kernel — SCTPhantom: SCTP ASCONF DEL-IP Use-After-Free Local Privilege Escalation (CVE-2026-64564)
CVE-2026-64564 binary Patched
CVE-2026-64564binaryHIGH 7.8Patched2026-08-15Linux Kernel — qdisc Rate-Table Race Condition Local Privilege Escalation (CVE-2026-68138)
CVE-2026-68138 binary Patched
CVE-2026-68138binaryHIGH 7.8Patched2026-08-15Zapscape — KVM/x86 Shadow-MMU Recursive-Zap Guest-to-Host Escape (CVE-2026-64561)
CVE-2026-64561 binary Patched
CVE-2026-64561binaryHIGH 8.8Patched2026-08-09MariaDB — Low-Privilege Remote Code Execution via ST_Area OOB Read + SYS_REFCURSOR Use-After-Free
MDEV-40328 (ST_Area OOB read); cursor-array UAF has no assigned CVE yet binary Unpatched
MDEV-40328binaryCRITICAL 8.8Unpatched2026-08-09ITScape — KVM/arm64 vGIC-ITS Guest-to-Host VM Escape (CVE-2026-46316)
CVE-2026-46316 (GHSA-qcxh-2cm7-9fcc) binary Patched
CVE-2026-46316binaryCRITICAL 9.3Patched2026-07-27Linux Kernel rtmutex Priority-Inheritance Stack-UAF — "GhostLock" (CVE-2026-43499, Nebula Security weaponized variant)
CVE-2026-43499 (aka "GhostLock") binary Patched
CVE-2026-43499binaryHIGH 7.8Patched2026-07-08RediShell: Redis Lua Scripting Use-After-Free Leading to JOP-Chained Remote Code Execution (CVE-2025-49844) EPSS 87%
CVE-2025-49844 binary Patched
CVE-2025-49844binaryCRITICAL 9.9Patched2026-07-06Windows Push Notification Service Use-After-Free Race (CVE-2026-42978)
CVE-2026-42978 binary Unverified
CVE-2026-42978binaryHIGH 7.8Unverified2026-07-05PinTheft: RDS zcopy Refcount-Steal Double-Free LPE — Pure NASM Rewrite (CVE-2026-43494)
CVE-2026-43494 binary Patched
CVE-2026-43494binaryHIGHPatched2026-07-05nginx Resolver Use-After-Free in OCSP Stapling (CVE-2026-40701)
CVE-2026-40701 web Patched
CVE-2026-40701webMEDIUM 6.3Patched2026-07-05Linux Kernel Futex-PI rtmutex remove_waiter() Use-After-Free (CVE-2026-43499)
CVE-2026-43499 binary Patched
CVE-2026-43499binaryHIGH 7.8Patched2026-07-05curl SMB Connection-Reuse Use-After-Free (CVE-2026-3805)
CVE-2026-3805 network Patched
CVE-2026-3805networkHIGHPatched2026-07-05AppleSEPKeyStore IOKit Use-After-Free (CVE-2026-20637)
CVE-2026-20637 binary Patched
CVE-2026-20637binaryHIGHPatched2026-07-05AppleM2ScalerCSCDriver Shared Scheduler Use-After-Free (CVE-2026-43655)
CVE-2026-43655 binary Unverified
CVE-2026-43655binaryHIGHUnverified2026-07-05AppleJPEGDriver startDecoder Timeout Use-After-Free (CVE-2026-20687)
CVE-2026-20687 binary Patched
CVE-2026-20687binaryHIGHPatched2026-07-05Redis Vector Set Duplicate HNSW Node ID RCE
None assigned as of 2026-07-03 network Unverified
None assigned as of 2026-07-03networkCRITICALUnverified2026-07-03libssh2 Publickey Subsystem List Parser Heap Corruption to Code Execution
None assigned as of 2026-07-03 network Unverified
None assigned as of 2026-07-03networkCRITICALUnverified2026-07-03Ladybird Browser WebAssembly ESM Host-Function Use-After-Free RCE
None assigned as of 2026-07-03 web Unverified
None assigned as of 2026-07-03webCRITICALUnverified2026-07-03c-ares TCP ares_getaddrinfo() Use-After-Free Code Execution
None assigned as of 2026-07-03 network Unverified
None assigned as of 2026-07-03networkHIGHUnverified2026-07-03PinTheft: RDS Double-Free → LPE
binary Unverified
—binaryHIGHUnverified2026-05-20Chrome WebGPU Use-After-Free (CVE-2026-5281) KEV
CVE-2026-5281 web Unverified
CVE-2026-5281webHIGH 8.8Unverified2026-05-18Chrome CSSFontFeatureValuesMap Use-After-Free (CVE-2026-2441) KEV EPSS 22%
CVE-2026-2441 web Unpatched
CVE-2026-2441webHIGH 8.8Unpatched2026-05-16HTTP Protocol Stack Remote Code Execution Vulnerability (CVE-2021-31166) KEV EPSS 100%
CVE-2021-31166 network Patched
CVE-2021-31166networkCRITICAL 9.8Patched2026-05-15