Exploit  H | EXPLOIT | GHDB |  2026  2025  2024  2023  2022  2021  2020  2019  2018  2017  2016  2015  2014  2013  2012  2011  2010  2009  2008  2007  2006  2005  2004  2003  2002  2001  2000 

H  Remote  Web App  Local&Privilege Escalation  DoS & PoC  ShellCode  Exp. kit  Typy Exploitů 


DATE

NAME

INFO

CATEGORY

SUBCATE

9.9.26

ShieldCrash Microsoft has failed to properly patch ShieldBreak CVE-2026-69414, under specific conditions it is still possible to trigger the exact same problem that was caused by ShieldBreak. While Microsoft fixed several things to prevent re-exploiting the issue, they missed a spot where ShieldBreak can still be exploited. EXPLOIT EXPLOIT

3.9.26

FalconFlank FalconFlank is a 0day privilege escalation that abuses the office malicious macros remediation in Crowdstrike Falcon Sensor, obviously by the time I drop this Crowdstrike would already have detections for it so if you want to test you either have to add it to the exclusions or obfuscate the PoC and change the dll load technique. As of now it works in a fully updated windows 11 25H2 / Windows Server 2025 with Crowdstrike Falcon - Phase 3 Optimal Protection + needs "Microsoft Office file malicious macro removal" EXPLOIT EXPLOIT

3.9.26

GreenSection Nvidia GreenSection Memory Corruption 0day vulnerability EXPLOIT EXPLOIT

3.9.26

ShieldBreak Windows Defender 0day vulnerability EXPLOIT EXPLOIT

3.9.26

BrokenArrow EXPLOIT EXPLOIT

3.9.26

LegacyHive Windows ProfSvc 0day EXPLOIT EXPLOIT

3.9.26

GreatXML GreatXML bitlocker bypass vulnerability EXPLOIT EXPLOIT

3.9.26

RoguePlanet RoguePlanet Windows Defender Vulnerability EXPLOIT EXPLOIT

1.9.26

PrettyPrague GenDigital Avast Antivirus ZeroDay Elevation of Privileges Vulnerability. Another zeroday in an antimalware provider, I'm not sure but I believe this vulnerability affect other GenDigital products as well (such as AVG, Norton...) EXPLOIT EXPLOIT

31.8.26

HardBreacher Kaspersky Antivirus For Endpoint ZeroDay Elevation of Privileges Vulnerability.So the problem is now leaking outside of Microsoft, there was poll held against either finding a bug in the home or commercial version and the poll results were the commercial version. EXPLOIT EXPLOIT

6.8.26

TONTOU: On the Exploitability of Time-of-Neutralization to Time-of-Use Windows Recently deployed Spectre v2 mitigations neutralize branch predictor state when switching privilege contexts or immediately prior to indirect branch execution, either through domain isolation or sanitization. These defenses assume that subsequent branch predictor behavior remains free from attacker influence until the neutralized state is used. EXPLOIT EXPLOIT

4.8.26

Critical N-able N-central Vulnerability and Active Exploitation N-able has disclosed a critical vulnerability impacting all current versions of N-central, including 2026.3, across both hosted and on‑prem deployments. The flaw can give attackers unauthenticated, "god-mode" access to the RMM console. EXPLOIT EXPLOIT

3.8.26

SonicWall SMA Exploit Chain From WSProxy to Root: INC ransomware and SonicWall SMA Exploit Chain EXPLOIT EXPLOIT

3.8.26

DarkSword DarkSword's Panel Sprawl: How One Body Hash Unravels a Six-Panel, Two-Codebase Operator Cluster EXPLOIT EXPLOIT

25.7.26

Cl0p Exploitation of PTC Windchill & FlexPLM (CVE-2026-12569) A coordinated Unified Threat Advisory covering active Cl0p ransomware affiliate exploitation of internet-exposed PTC Windchill and FlexPLM deployments — chaining a pre-auth FlexPLM WSDL information disclosure with a Windchill login servlet flaw for unauthenticated RCE, JSP webshell deployment, and double-extortion data theft. EXPLOIT EXPLOIT

25.7.26

Fastjson RCE (≤1.2.83): Active Exploitation Detected — Detection & Mitigation A remote code execution vulnerability in Fastjson affects every version up to and including 1.2.83. A remote attacker can run arbitrary code on a vulnerable server by sending it specially crafted JSON — no user privileges, no victim interaction, and no third-party libraries required. ThreatBook TDP® (Threat Detection Platform) has already captured this vulnerability being exploited in the wild, so if you run an affected version without SafeMode enabled, treat remediation as urgent. EXPLOIT EXPLOIT

21.7.26

SonicWall Secure Mobile Access 0-day Exploitation Proxying to Compromise: SonicWall Secure Mobile Access 0-day Exploitation EXPLOIT EXPLOIT
20.6.26 PoisonX BYOVD Driver Bypasses CrowdStrike EDR Microsoft-signed kernel driver used in a BYOVD attack to kill CrowdStrike Falcon. Learn how the driver’s hidden IOCTL enables process termination from kernel mode and why modern EDR solutions can be bypassed. EXPLOIT EXPLOIT
20.6.26 Bomgar RMM Exploitation Threat Advisory: Uptick in Bomgar RMM Exploitation EXPLOIT EXPLOIT
20.6.26 usbliter8 An A12/A13 SecureROM exploit EXPLOIT EXPLOIT
12.5.26 Actively Exploits CVE-2026-41940 CVE-2026-41940 is a high-severity unauthenticated authentication bypass vulnerability affecting cPanel & WHM. This product is widely used in Linux server operations and virtual hosting management. EXPLOIT EXPLOIT
26.3.26 Coruna Coruna: the framework used in Operation Triangulation EXPLOIT EXPLOIT
4.3.26 Coruna Coruna: The Mysterious Journey of a Powerful iOS Exploit Kit EXPLOIT EXPLOIT
26.2.26 RoguePilot RoguePilot: Exploiting GitHub Copilot for a Repository Takeover EXPLOIT EXPLOIT
13.2.26 MOONSHINE Exploit Kit MOONSHINE Exploit Kit and DarkNimbus Backdoor Enabling Earth Minotaur’s Multi-Platform Attacks EXPLOIT EXPLOIT KIT
3.2.26 Metro4Shell Metro4Shell: Exploitation of React Native’s Metro Server in the Wild EXPLOIT EXPLOIT