PoC Archive PoC Archive

network PoCs

subscribe (RSS)

Proof-of-concept research filed under the network category.

Entries

126

in network

CISA KEV

38

exploited in the wild

Ransomware

7

known campaign use

Unpatched

59

no vendor fix

Critical

77

61% of listed

126 entries

Severity

Exploitation signals

Patch status

Date range

→
Sort

126 result(s)

NETWORK LIST 126 shown · 126 indexed
PoC titleSeverity
UniFi OS -- Unauthenticated Command Injection RCE (CVE-2026-34910) KEV EPSS 87%
CVE-2026-34910, CVE-2026-34909, CVE-2026-34908 network Patched
CRITICAL 10
Citrix NetScaler ADC/Gateway -- Pre-Auth SAML PrefixList Heap Overflow to RCE (CVE-2026-8452) KEV
CVE-2026-8452 network Patched
CRITICAL 9.8
Cisco IMC Argument Injection to Root RCE (CVE-2026-20200)
CVE-2026-20200 / NSIDE-SA-2026-003 network Patched
CRITICAL 9.9
Microsoft SCCM — AdminService CAB Extraction Path-Traversal to SYSTEM RCE (CVE-2026-47301)
CVE-2026-47301 network Unverified
CRITICAL 9.8
Windows Kerberos — ResetNightmare: Arbitrary Password Reset via Change Password Protocol Validation Flaw (CVE-2026-27912)
CVE-2026-27912 network Unverified
HIGH 8
Active Directory — SPN Unicode Collision Detection Scanner (CVE-2026-25177)
CVE-2026-25177 network Patched
HIGH 8.8
Ivanti Endpoint Manager Mobile (EPMM) Unauthenticated Remote API Access (CVE-2023-35078) KEV RW EPSS 100%
CVE-2023-35078 (Ivanti advisory; CWE-287 per NVD) network Unverified
CRITICAL 9.8
Ivanti Connect Secure / Policy Secure / ZTA Gateways Remote Unauthenticated Stack-Based Buffer Overflow (CVE-2025-22457) KEV RW EPSS 100%
CVE-2025-22457 network Unpatched
CRITICAL 9
Check Point Security Management / Multi-Domain Server SmartConsole Authentication Bypass via Forged Application Certificate Bind (CVE-2026-16232) KEV EPSS 72%
CVE-2026-16232 network Patched
CRITICAL 9.1
CVE-2022-40684 — FortiOS / FortiProxy / FortiSwitchManager Authentication Bypass (vamp-forticheck Scanner) KEV RW EPSS 100%
CVE-2022-40684 network Unverified
CRITICAL 9.8
Windows Message Queuing (MSMQ) Queue Manager Heap-Based Buffer Overflow (CVE-2026-54992)
CVE-2026-54992 network Patched
HIGH 8.4
AD CS/AD FS Enrollment "cdc" Chase Attribute Abuse → Domain Controller Impersonation (CertiGhost, CVE-2026-54121)
CVE-2026-54121 network Patched
HIGH 8.8
Cisco Unified Communications Manager WebDialer SSRF → Arbitrary File Write → Root (CVE-2026-20230) KEV EPSS 88%
CVE-2026-20230 (cisco-sa-cucm-ssrf-cXPnHcW) network Patched
CRITICAL 8.6
SonicWall SMA1000 WorkPlace SSRF → Internal Erlang RPC Remote Code Execution (CVE-2026-15409) KEV RW EPSS 84%
CVE-2026-15409 (SNWLID-2026-0008) network Patched
CRITICAL 10
OpenSSH Forwarded-Agent Lock/Unlock State Confusion → Unauthorized PKCS#11 Provider Load (No CVE)
network Unpatched
HIGH
D-Link DIR-820L `get_set.ccp` LAN Configuration OS Command Injection (CVE-2022-26258) KEV EPSS 80%
CVE-2022-26258 network Unverified
CRITICAL 9.8
XRING — XQUIC QPACK Ring Buffer Resize Underflow (Remote Unauthenticated DoS)
network Unpatched
CRITICAL
XSpeeder SXZOS Pre-Auth eval() Remote Code Execution (CVE-2025-54322) EPSS 15%
CVE-2025-54322 network Unpatched
CRITICAL 10
Twonky Server 8.5.2 Unauthenticated `/nmc/rpc/` Auth Bypass & Admin Credential Log Leak (CVE-2025-13315) EPSS 33%
CVE-2025-13315 network Unpatched
CRITICAL 9.8
Tenda AC9 `AdvSetMacMtuWan` Stack-Based Buffer Overflow (CVE-2025-29384)
CVE-2025-29384 network Unpatched
CRITICAL 9.8
Squid Proxy Sensitive Header Leak via Error Page `mailto:` Diagnostic Block (CVE-2025-62168) EPSS 63%
CVE-2025-62168 network Patched
CRITICAL 10
React Native Community CLI Metro Dev Server `/open-url` OS Command Injection (CVE-2025-11953) KEV EPSS 94%
CVE-2025-11953 network Patched
CRITICAL 9.8
Monsta FTP Pre-Authentication Remote Code Execution via Arbitrary File Upload (CVE-2025-34299) EPSS 73%
CVE-2025-34299 network Patched
CRITICAL 9.8
Mitel MiCollab Path Normalization Bypass to Internal Endpoints (CVE-2025-52913)
CVE-2025-52913 network Unverified
CRITICAL 9.8
HPE OneView `id-pools/executeCommand` OS Command Injection (CVE-2025-37164) KEV EPSS 90%
CVE-2025-37164 network Unpatched
CRITICAL 10
FreePBX Framework Module Authentication Bypass via Forged Authorization Header (CVE-2025-66039)
CVE-2025-66039 network Patched
CRITICAL 9.8
FortiWeb `cgi-bin/fwbcgi` Path Traversal Authentication Bypass Leading to Rogue Admin Creation (CVE-2025-64446) KEV EPSS 92%
CVE-2025-64446 network Unverified
CRITICAL 9.8
FortiOS/FortiProxy/FortiSwitchManager/FortiWeb FortiCloud SSO Authentication Bypass Detection Tool (CVE-2025-59718) KEV EPSS 69%
CVE-2025-59718 (Fortinet advisory FG-IR-25-647; related: CVE-2025-59719) network Patched
CRITICAL 9.8
FiberHome HG6145F1 Predictable Default Wi-Fi PSK Derived from Broadcast SSID (CVE-2025-63353)
CVE-2025-63353 / GHSA-cg2x-c25f-6327 network Patched
CRITICAL 9.8
D-Link AX1500 SetDeviceSettings `DeviceName` OS Command Injection (CVE-2025-60854)
CVE-2025-60854 network Patched
CRITICAL 9.8
ConnectWise Automate Adversary-in-the-Middle Remote Code Execution (CVE-2025-11492)
CVE-2025-11492 network Patched
CRITICAL 9.6
Cisco AsyncOS Spam Quarantine (TCP/6025) Exposure & IOC Scanner (CVE-2025-20393) KEV EPSS 30%
CVE-2025-20393 network Unverified
CRITICAL 10
Cisco ASA/FTD WebVPN File-Handler Heap Buffer Overflow Exposure Scanner (CVE-2025-20333) KEV EPSS 71%
CVE-2025-20333 network Unverified
CRITICAL 9.9
ASP.NET Core Kestrel HTTP Request Smuggling (CVE-2025-55315) EPSS 66%
CVE-2025-55315 network Patched
CRITICAL 9.9
Zyxel VMG3625-T50B Authenticated Command Injection to Root SSH Access (CVE-2026-1459)
CVE-2026-1459 network Unverified
HIGH
ZTE ZXHN H298A / H108N Router Unauthenticated Credential Disclosure (CVE-2026-34474) EPSS 25%
CVE-2026-34474 network Unverified
HIGH
ZTE ZXHN H188A Unauthenticated Wizard Handler Credential Disclosure / Auth Bypass (CVE-2026-34472)
CVE-2026-34472 network Unverified
CRITICAL
ZTE Router Unauthenticated Oversized-POST Denial of Service (CVE-2026-34473)
CVE-2026-34473 network Unverified
HIGH
ZAI-Shell — Unauthenticated Remote Code Execution via P2P Terminal Sharing (CVE-2026-25807)
CVE-2026-25807 network Patched
CRITICAL
YAMCS LdapAuthModule LDAP Injection Authentication Bypass (CVE-2026-42568)
CVE-2026-42568 / GHSA-cqh3-jg8p-336j network Patched
MEDIUM
Wyze Cam Pan v3 / TUTK SDK — tutk_packet_alloc Heap Overflow (CVE-2026-38698)
CVE-2026-38698 network Unverified
CRITICAL
Windows Server 2025 Local NTLM Reflection LPE via SMB Arbitrary Port + PetitPotam (CVE-2026-24294)
CVE-2026-24294 (Microsoft Security Response Center) network Patched
CRITICAL
Windows Kerberos Reflection via Unicode SPN Normalization Bypass (CVE-2026-26128)
CVE-2026-26128 network Unverified
CRITICAL
Windows ikeext.dll IKEv2 Double-Free Remote Kernel Exploit — CVE-2026-33824 KEV EPSS 73%
CVE-2026-33824 network Patched
CRITICAL
Unauthenticated NaN Injection via MAVLink PARAM_SET in ArduPilot ArduPlane (CVE-2026-36522)
CVE-2026-36522 network Unverified
CRITICAL 9.1
TP-Link Tapo C260 Unauthenticated-to-Root RCE Chain — CVE-2026-0651
CVE-2026-0651 (chained with CVE-2026-0652, CVE-2026-0653) network Unverified
CRITICAL
TP-Link DHCP Option 66 Unauthenticated RCE — CVE-2026-11834
CVE-2026-11834 network Unverified
CRITICAL
TP-Link Archer C64 Web UI Rate-Limit Bypass via Residual Debug SSH Service (CVE-2026-8697)
CVE-2026-8697 network Unverified
CRITICAL 9.3
Tenda HG7/HG9/HG10 Router Stack-Based Buffer Overflow — CVE-2026-11499
CVE-2026-11499 network Unverified
HIGH
Tasmota fetch_jpg() strcpy() Buffer Overflow in boundary[40] (CVE-2026-38426)
CVE-2026-38426 network Patched
CRITICAL 9.8
Tasmota fetch_jpg() Integer Wraparound to Heap Corruption (CVE-2026-38427)
CVE-2026-38427 network Patched
CRITICAL 9.8
Tasmota fetch_jpg() Combined Buffer Overflow RCE Chain (CVE-2026-38422)
CVE-2026-38422 network Patched
CRITICAL 9.8
strongSwan RADIUS Attribute-Iterator Pre-Auth Infinite Loop / Remote DoS (CVE-2026-35333)
CVE-2026-35333 network Unverified
MEDIUM
strongSwan EAP-SIM/EAP-AKA Pre-Auth Heap Buffer Overflow via Integer Underflow (CVE-2026-35330)
CVE-2026-35330 network Unverified
HIGH
Sparx Enterprise Architect / Pro Cloud Server Unauthenticated Binary-Protocol SQL Injection (CVE-2026-42096)
CVE-2026-42096 network Unverified
CRITICAL
SonicWall SMA 8200v Cross-Parameter Blind SQL Injection to Root (CVE-2026-4112)
CVE-2026-4112 (SonicWall Advisory SNWLID-2026-0003) network Unverified
HIGH 7.2
Sliver C2 Server mTLS Nil-Pointer Panic / Infrastructure Kill-Switch — CVE-2026-29781
CVE-2026-29781 (GHSA-hx52-cv84-jr5v) network Unverified
HIGH
Samba spoolss Print Job Command Injection RCE (CVE-2026-4480) EPSS 14%
CVE-2026-4480 network Patched
CRITICAL
Realtek rtl819x Jungle SDK Unauthenticated Kernel Memory R/W via Debug IOCTLs (CVE-2026-36355)
CVE-2026-36355 network Unverified
CRITICAL
ProFTPD mod_sql Pre-Auth SQL Injection Leading to RCE (CVE-2026-42167)
CVE-2026-42167 network Patched
HIGH 8.1
PJSIP DNS Compression Pointer Heap Out-of-Bounds Read (CVE-2026-32945)
CVE-2026-32945 network Patched
MEDIUM
PJSIP / PJNATH ICE Session Stack Buffer Overflow via SDP ice-ufrag (CVE-2026-25994)
CVE-2026-25994 network Patched
HIGH
PgBouncer SASL Length Field Integer Overflow Crash — CVE-2026-6664
CVE-2026-6664 network Patched
HIGH
OpenClaw Gateway WebSocket Authentication Bypass RCE — CVE-2026-28466
CVE-2026-28466 network Patched
CRITICAL
OpenBSD slaacd/rad Infinite Loop via Malformed ND Option (CVE-2026-41285)
CVE-2026-41285 network Patched
HIGH
NVIDIA Triton Inference Server SageMaker Auth Bypass to Unauthenticated RCE (CVE-2026-24207)
CVE-2026-24207 (sibling: CVE-2026-24206, Vertex AI, analysis only) network Patched
CRITICAL 9.8
Neo4j Bolt Transaction Metadata Log Injection (CVE-2026-1337)
CVE-2026-1337 network Unverified
LOW
MR9600 Router Bluetooth/JNAP Management Interface RCE Injection (CVE-2026-6992)
CVE-2026-6992 network Unverified
HIGH
MeiG Smart FORGE_SLT711 GoAhead Unauthenticated OS Command Injection (CVE-2026-36356) EPSS 14%
CVE-2026-36356 network Unverified
CRITICAL
MariaDB server_audit Plugin Logging Bypass via Inline Comments (CVE-2026-3494)
CVE-2026-3494 network Patched
MEDIUM
lwIP SNMPv3 USM Stack-Based Buffer Overflow (CVE-2026-8836)
CVE-2026-8836 network Patched
CRITICAL 9.8
LiteSpeed cPanel/WHM Plugin Symlink Privilege Escalation — CVE-2026-54420 KEV
CVE-2026-54420 network Unverified
HIGH 8.5
Linux Kernel ICMP Fragmentation-Needed NULL Pointer Dereference (CVE-2026-23398)
CVE-2026-23398 network Patched
HIGH
Ivanti EPMM Pre-Auth RCE via Bash Arithmetic Expansion (CVE-2026-1281 / CVE-2026-1340) KEV EPSS 82%
CVE-2026-1281, CVE-2026-1340 network Patched
CRITICAL
HPE Aruba AOS-CX Pre-Auth REST API Bypass via nginx Version Smuggling (CVE-2026-23813)
CVE-2026-23813 network Patched
CRITICAL 9.8
HAProxy HTTP/3 (QUIC) Standalone FIN Body Validation Bypass Leading to Request Smuggling — CVE-2026-33555
CVE-2026-33555 network Patched
HIGH
gRPC-Go RBAC Authorization Bypass via Missing Leading Slash in `:path` (CVE-2026-33186)
CVE-2026-33186 (GHSA-p77j-4mvh-x3m3) network Patched
HIGH
GRASSMARLIN XML External Entity (XXE) Out-of-Band File Exfiltration (CVE-2026-6807)
CVE-2026-6807 network Unverified
HIGH
GNU InetUtils telnetd LINEMODE SLC Pre-Auth Buffer Overflow (CVE-2026-32746) EPSS 24%
CVE-2026-32746 network Unverified
CRITICAL 9.8
FortiSandbox 4.4.0-4.4.8 — OS Command Injection via tracer-behavior Endpoint (CVE-2026-39808) KEV EPSS 93%
CVE-2026-39808 network Unverified
CRITICAL 9.8
Fortinet FortiSandbox "Start VNC" OS Command Injection (CVE-2026-25089) KEV EPSS 76%
CVE-2026-25089 network Patched
CRITICAL 9.8
dnsmasq extract_addresses() RDLEN/RDATA Buffer Overflow — CVE-2026-5172
CVE-2026-5172 network Patched
INFO
dnsmasq EDNS Client Subnet (ECS) Response Validation Bypass (CVE-2026-4893)
CVE-2026-4893 network Patched
MEDIUM
curl SMB Connection-Reuse Use-After-Free (CVE-2026-3805)
CVE-2026-3805 network Patched
HIGH
Cisco Catalyst SD-WAN Peering Authentication Bypass — CVE-2026-20182 KEV EPSS 92%
CVE-2026-20182 network Patched
CRITICAL 10
BIRD/BIRD2 BGP AS_PATH Mask Matching Stack Buffer Overflow (CVE-2026-49943)
CVE-2026-49943 network Patched
HIGH 3.1
Arista EOS Tunnel Decapsulation Protocol-Type Bypass — CVE-2026-7473 KEV
CVE-2026-7473 network Unverified
MEDIUM 5.8
Apache MINA acceptMatchers Deserialization Filter Bypass to RCE (CVE-2026-42779)
CVE-2026-42779 network Patched
CRITICAL 9.8
Apache HTTP Server HTTP/2 HPACK Cookie-Merging Memory Bomb (CVE-2026-49975) EPSS 31%
CVE-2026-49975 network Unverified
HIGH
Apache ActiveMQ Classic Jolokia addNetworkConnector Xbean Spring-XML RCE (CVE-2026-34197) KEV EPSS 97%
CVE-2026-34197 (related bypass: CVE-2026-42588) network Patched
CRITICAL
Algorithmic Complexity DoS in musl libc `iconv` GB18030 Decoder — CVE-2026-6042
CVE-2026-6042 network Unverified
HIGH 7.5
PostgreSQL Referential-Integrity Owner-Switched Implicit Cast RCE
None assigned as of 2026-07-04 network Unverified
HIGH
RustDesk Relay Session Downgrade and FileTransfer Authorization Scope Bypass
None assigned as of 2026-07-03 network Unverified
HIGH
Redis Vector Set Duplicate HNSW Node ID RCE
None assigned as of 2026-07-03 network Unverified
CRITICAL
OpenVPN Connect Server-Pushed Option Current-User Command Execution
None assigned as of 2026-07-03 network Unverified
HIGH
Nmap IPv6 Extension-Header Length Wrap
None assigned as of 2026-07-03 network Unverified
LOW
nghttpx HTTP/1.1 Upgrade Request Body Response Queue Poisoning
None assigned as of 2026-07-03 network Patched
HIGH
libssh2 Unchecked SSH packet_length Integer Wrap to RCE (CVE-2026-55200)
CVE-2026-55200 network Patched
CRITICAL
libssh2 Publickey Subsystem List Parser Heap Corruption to Code Execution
None assigned as of 2026-07-03 network Unverified
CRITICAL
Fortinet FortiClient EMS Pre-Auth Bypass — "FortiBleed" (CVE-2026-35616) KEV EPSS 91%
CVE-2026-35616 network Patched
CRITICAL 9.1
curl SMTP EXPN Recipient CRLF Command Injection
None assigned as of 2026-07-03 network Unverified
MEDIUM
Citrix NetScaler ADC/Gateway Pre-Auth SAML Memory Overread — "CitrixBleed"-style Leak (CVE-2026-8451) EPSS 16%
CVE-2026-8451 network Unverified
HIGH 7.5
c-ares TCP ares_getaddrinfo() Use-After-Free Code Execution
None assigned as of 2026-07-03 network Unverified
HIGH
Squidbleed — Squid Proxy FTP Gateway Out-of-Bounds Heap Read (CVE-2026-47729)
CVE-2026-47729 network Patched
MEDIUM
Cisco Unified CM WebDialer SSRF to Arbitrary File Write / RCE (CVE-2026-20230) KEV EPSS 88%
CVE-2026-20230 network Unverified
CRITICAL 8.6
Cisco Catalyst SD-WAN Manager Arbitrary File Write (CVE-2026-20262) KEV EPSS 28%
CVE-2026-20262 network Unverified
MEDIUM 6.5
libssh2 SSH Packet Length OOB Heap Write / Unauthenticated RCE (CVE-2026-55200)
CVE-2026-55200 network Patched
CRITICAL 9.8
libcurl mTLS Connection Reuse Authentication Bypass (CVE-2026-8932)
CVE-2026-8932 network Patched
LOW
GNU Inetutils telnetd Unauthenticated Root RCE via NEW-ENVIRON (CVE-2026-24061) KEV EPSS 98%
CVE-2026-24061 network Patched
CRITICAL 9.8
GeoVision GV-I/O Box 4E DVRSearch Unauthenticated Stack Buffer Overflow RCE (CVE-2026-12485)
CVE-2026-12485 network Patched
CRITICAL 10
Ubiquiti UniFi OS Unauthenticated RCE Chain (CVE-2026-34908 / CVE-2026-34909 / CVE-2026-34910) KEV EPSS 85%
CVE-2026-34908, CVE-2026-34909, CVE-2026-34910 network Patched
CRITICAL 10
Ivanti Sentry Pre-Auth RCE + Auth Bypass (CVE-2026-10520 / CVE-2026-10523) KEV EPSS 100%
CVE-2026-10520, CVE-2026-10523 network Patched
CRITICAL 10
Cisco Catalyst SD-WAN Manager Privilege Escalation (CVE-2026-20245) KEV EPSS 25%
CVE-2026-20245 network Unpatched
HIGH 7.8
Check Point Remote Access VPN IKEv1 Auth Bypass (CVE-2026-50751) KEV RW EPSS 84%
CVE-2026-50751 network Patched
CRITICAL 9.3
Netlogon CLDAP Stack Buffer Overflow (CVE-2026-41089) EPSS 80%
CVE-2026-41089 network Patched
CRITICAL 9.8
TossUp — TerraMaster TOS Unauthenticated Redis Root RCE + NFS LPE
N/A (vendor confirmed TOS4 is EOL; no fix planned) network Unpatched
CRITICAL
Ivanti Connect Secure Pre-Auth RCE (Stack Overflow) KEV RW EPSS 100%
CVE-2025-0282 network Unverified
CRITICAL 9
Fortinet FortiManager FortiJump Unauthenticated RCE (CVE-2024-47575) KEV EPSS 95%
CVE-2024-47575 network Unverified
CRITICAL 9.8
Fortinet FortiCloud SSO Authentication Bypass KEV EPSS 69%
CVE-2025-59718, CVE-2025-59719 (Advisory: FG-IR-25-647) network Unverified
CRITICAL 9.8
Erlang/OTP SSH Pre-Auth RCE - CVE-2025-32433 KEV EPSS 99%
CVE-2025-32433 network Patched
CRITICAL 10
VMware vCenter Server DCE/RPC Heap Overflow RCE (CVE-2024-37079) KEV EPSS 22%
CVE-2024-37079 network Patched
CRITICAL 9.8
VMware ESXi Active Directory Authentication Bypass (CVE-2024-37085) KEV RW EPSS 27%
CVE-2024-37085 network Patched
MEDIUM 6.8
OpenSSH regreSSHion Signal-Handler Race Unauthenticated RCE (CVE-2024-6387) EPSS 100%
CVE-2024-6387 network Patched
HIGH 8.1
LDAP Nightmare — Windows LDAP Client RCE/DoS (CVE-2024-49113) EPSS 83%
CVE-2024-49113 network Patched
CRITICAL
HTTP Protocol Stack Remote Code Execution Vulnerability (CVE-2021-31166) KEV EPSS 100%
CVE-2021-31166 network Patched
CRITICAL 9.8
BlueDucky — Unauthenticated Peering Leading to Code Execution (CVE-2023-45866)
CVE-2023-45866 network Patched
HIGH 8.8