PoC Archive PoC Archive

tag

Zero-Day

  • N/A binary HIGH

    GreatXML — WinRE / Defender Offline-Scan Trust-Boundary Abuse → BitLocker Bypass (No CVE)

    GreatXML abuses the trust boundary around Microsoft Defender's Offline Scan feature, which reboots a Windows machine into WinRE (Windows PE) and runs OfflineScannerShell.exe with elevated, pre-BitLocker-unlock trust. The ReAgent.xml recovery-configuration…

    Unpatched 2026-07-27
  • CVE-2026-11645 web HIGH 8.8 KEV

    Google Chromium V8 Out-of-Bounds Read/Write — Crash PoC (CVE-2026-11645)

    CVE-2026-11645 is a high-severity out-of-bounds read/write vulnerability in V8, the JavaScript/WebAssembly engine used by Chrome and other Chromium-based browsers. The bug is rooted in V8's TurboFan optimizer: incorrect range analysis for loop-modified or…

    Unverified 2026-07-01
  • CVE-2026-45586 binary HIGH 7.8

    Windows CTFMON Arbitrary Section Object EoP — GreenPlasma (CVE-2026-45586)

    CVE-2026-45586 (GreenPlasma) is a Windows CTFMON Elevation of Privilege vulnerability exploiting an arbitrary named section object creation primitive. A standard unprivileged user can create a section object in any directory object writable by SYSTEM, abusing…

    Patched 2026-06-28
  • CVE-2026-45585 misc MEDIUM 6.1

    YellowKey — BitLocker Bypass via WinRE autofstx.exe (CVE-2026-45585)

    CVE-2026-45585 (YellowKey) is a zero-day physical-access vulnerability discovered in May 2026 that allows an attacker with physical access to a Windows 11 device to fully bypass BitLocker disk encryption without the PIN, password, or recovery key. The…

    Patched 2026-06-26
  • CVE-2025-26633 binary HIGH KEV Ransomware EPSS 30%

    Windows MMC MSC EvilTwin - CVE-2025-26633

    CVE-2025-26633 is a zero-day vulnerability in Microsoft Management Console (MMC) that was exploited in the wild by Russian APT group Water Gamayun (EncryptHub/Larva-208). An attacker crafts a malicious .msc file that abuses the MUIPath resolution mechanism:…

    Unverified 2026-05-17
  • CVE-2024-3400 web CRITICAL 10 KEV Ransomware EPSS 100%

    Palo Alto PAN-OS GlobalProtect Unauthenticated RCE (CVE-2024-3400)

    CVE-2024-3400 is an unauthenticated command injection vulnerability in PAN-OS GlobalProtect that can be reached over the network when specific features are enabled. Public reporting showed chained abuse via arbitrary file creation and command execution as…

    Patched 2026-05-17
  • CVE-2025-0282 network CRITICAL 9 KEV Ransomware EPSS 100%

    Ivanti Connect Secure Pre-Auth RCE (Stack Overflow)

    CVE-2025-0282 is a pre-authentication stack-based buffer overflow in the IFT (IF-T) TLS protocol handling code of Ivanti Connect Secure VPN appliances. Discovered and disclosed by Sina Kheirkhah of watchTowr Labs, this zero-day was confirmed by Mandiant as…

    Unverified 2026-05-17
  • CVE-2024-47575 network CRITICAL 9.8 KEV EPSS 95%

    Fortinet FortiManager FortiJump Unauthenticated RCE (CVE-2024-47575)

    CVE-2024-47575 (FortiJump) is a missing-authentication flaw in FortiManager's fgfmd daemon that lets a remote unauthenticated attacker execute arbitrary commands. Public exploit code demonstrates vulnerability detection and command execution primitives over…

    Unverified 2026-05-17