Vulnerabilities & exploits
Exploit catalogue
Zero-days from our own research and n-days recovered from intrusions. Each write-up gives the class, the impact, how to detect it, and a link to public proof-of-concept.
Exploits
9
4 targets
With a CVE
9
assigned
In CISA KEV
0
known exploited
With full report
1
linked teardown
httpx2 3
- httpx2 remote code execution (CVE-2026-84378) CVSS 5.9 Medium
CVE-2026-84378n-day Arbitrary code execution against the vulnerable build September 2, 2026 - httpx2 remote code execution (CVE-2026-84380) CVSS 5.6 Medium
CVE-2026-84380n-day Arbitrary code execution against the vulnerable build September 2, 2026 - httpx2 remote code execution (CVE-2026-84382) CVSS 7.5 High
CVE-2026-84382n-day Arbitrary code execution against the vulnerable build September 2, 2026
vllm 4
- vllm remote code execution (CVE-2026-71486) CVSS 4.3 Medium
CVE-2026-71486n-day Arbitrary code execution from loading untrusted input August 17, 2026 - vllm remote code execution (CVE-2026-73560) CVSS 6.5 Medium
CVE-2026-73560n-day Arbitrary code execution against the vulnerable build August 17, 2026 - vllm remote code execution (CVE-2026-73557) CVSS 6.3 Medium
CVE-2026-73557n-day Arbitrary code execution from loading untrusted input August 13, 2026 - vllm remote code execution (CVE-2026-73558) CVSS 5.3 Medium
CVE-2026-73558n-day Arbitrary code execution against the vulnerable build August 13, 2026
Linux kernel 1
- getroot — AF_ALG page-cache LPE and container escape CVSS 8.8 High
CVE-2026-31431n-day Local privilege escalation to root, with escape from a container to the host June 15, 2026
PyYAML 1
- PyYAML FullLoader deserialization RCE (CVE-2020-14343) CVSS 9.8 Critical
CVE-2020-14343n-day Arbitrary code execution from loading untrusted input February 9, 2021
No exploits match that filter.
Proof of concept & handling
Where a proof-of-concept is already public, the write-up links straight to it. Everything catalogued here is real and some of it is working exploit code, so run any of it in a disposable VM with no route to a network you use. For anything without a public link, email [email protected] and say who you are and what you need it for.