network PoCs
subscribe (RSS)Proof-of-concept research filed under the network category.
Entries
126
in network
CISA KEV
36
exploited in the wild
Ransomware
7
known campaign use
Unpatched
59
no vendor fix
Critical
77
61% of listed
Severity
Exploitation signals
Patch status
Date range
126 result(s)
- CVE-2026-34910, CVE-2026-34909, CVE-2026-34908 network CRITICAL 10 KEV EPSS 87%
UniFi OS -- Unauthenticated Command Injection RCE (CVE-2026-34910)
CVE-2026-34910 is an unauthenticated command injection vulnerability in Ubiquiti UniFi OS Server, rated CVSS 10.0 and listed in CISA KEV. The nginx auth layer treats any request whose raw URI starts with /api/auth/validate-sso/ as public, but routes by the…
Patched 2026-08-16 - CVE-2026-8452 network CRITICAL 9.8
Citrix NetScaler ADC/Gateway -- Pre-Auth SAML PrefixList Heap Overflow to RCE (CVE-2026-8452)
CVE-2026-8452 is a pre-authentication heap buffer overflow in the Citrix NetScaler ADC and Gateway SAML authentication handler. The vulnerability exists in the XML Signature Canonicalization (C14N) processing of the PrefixList attribute within SAML responses.…
Patched 2026-08-16 - CVE-2026-20200 / NSIDE-SA-2026-003 network CRITICAL 9.9
Cisco IMC Argument Injection to Root RCE (CVE-2026-20200)
CVE-2026-20200 is an argument injection vulnerability in Cisco IMC that allows an authenticated user to achieve root-level RCE. The Redfish API SSH key upload handler (ManagerAccount.UploadSSHKey) passes the KeyURI parameter to curl without sanitization. An…
Patched 2026-08-16 - CVE-2026-47301 network CRITICAL 9.8
Microsoft SCCM — AdminService CAB Extraction Path-Traversal to SYSTEM RCE (CVE-2026-47301)
CVE-2026-47301 is a remote code execution vulnerability in Microsoft Configuration Manager (SCCM) that chains four weaknesses: broken access control on the AdminService UploadExtensionInChunks endpoint (any domain user, no RBAC check), CAB extraction…
Unverified 2026-08-15 - CVE-2026-27912 network HIGH 8
Windows Kerberos — ResetNightmare: Arbitrary Password Reset via Change Password Protocol Validation Flaw (CVE-2026-27912)
CVE-2026-27912, nicknamed ResetNightmare by Semperis, is a validation flaw in the Kerberos Change Password protocol that allows an attacker to reset the password of any user or computer account in Active Directory — including Domain Admins, the krbtgt…
Unverified 2026-08-11 - CVE-2026-25177 network HIGH 8.8
Active Directory — SPN Unicode Collision Detection Scanner (CVE-2026-25177)
CVE-2026-25177 is a privilege escalation vulnerability in Active Directory Domain Services caused by improper restriction of Unicode characters in Service Principal Names (SPNs). An authenticated user with write-SPN permissions can inject Unicode zero-width…
Patched 2026-08-11 - CVE-2023-35078 network CRITICAL 9.8 KEV Ransomware EPSS 100%
Ivanti Endpoint Manager Mobile (EPMM) Unauthenticated Remote API Access (CVE-2023-35078)
Ivanti Endpoint Manager Mobile (EPMM, formerly MobileIron Core) fails to enforce authentication on specific paths beneath its /mifs/aad/api/ administrative API. An unauthenticated remote attacker can issue a plain GET…
Unverified 2026-08-09 - CVE-2025-22457 network CRITICAL 9 KEV Ransomware EPSS 100%
Ivanti Connect Secure / Policy Secure / ZTA Gateways Remote Unauthenticated Stack-Based Buffer Overflow (CVE-2025-22457)
CVE-2025-22457 is a remote, pre-authentication stack-based buffer overflow (CWE-121) in the HTTPS request-handling path of Ivanti Connect Secure and sibling appliances. A single oversized X-Forwarded-For request header overflows a fixed-size stack buffer in…
Unpatched 2026-08-09 - CVE-2026-16232 network CRITICAL 9.1 KEV EPSS 71%
Check Point Security Management / Multi-Domain Server SmartConsole Authentication Bypass via Forged Application Certificate Bind (CVE-2026-16232)
CVE-2026-16232 is an unauthenticated authentication bypass (CWE-287) in the Check Point SmartConsole login path on Security Management and Multi-Domain Management servers. During the legacy SIC/CPMI bootstrap the management server volunteers its own SIC…
Patched 2026-08-09 - CVE-2022-40684 network CRITICAL 9.8 KEV Ransomware EPSS 100%
CVE-2022-40684 — FortiOS / FortiProxy / FortiSwitchManager Authentication Bypass (vamp-forticheck Scanner)
CVE-2022-40684 is an authentication-bypass vulnerability in the web management interface of FortiOS, FortiProxy, and FortiSwitchManager that allows an unauthenticated remote attacker to access the administrative REST API. The affected firmware fails to…
Unverified 2026-07-31 - CVE-2026-54992 network HIGH 8.4
Windows Message Queuing (MSMQ) Queue Manager Heap-Based Buffer Overflow (CVE-2026-54992)
MSMQ's Queue Manager processes RStartReceive/RStartTransactionalReceive responses from the MS-MQRR RPC interface as a set of SectionBuffer structures, each carrying its own SectionSizeAlloc. When a remote-read response is split into multiple sections,…
Patched 2026-07-27 - CVE-2026-54121 network HIGH 8.8
AD CS/AD FS Enrollment "cdc" Chase Attribute Abuse → Domain Controller Impersonation (CertiGhost, CVE-2026-54121)
CertiGhost (CVE-2026-54121) abuses a "chase" mechanism in AD CS certificate enrollment: when a certificate request carries a cdc (chase domain controller) attribute pointing at an attacker-controlled IP alongside an rmd (remote machine DNS) attribute naming a…
Patched 2026-07-27 - CVE-2026-20230 network CRITICAL 8.6 KEV EPSS 83%
Cisco Unified Communications Manager WebDialer SSRF → Arbitrary File Write → Root (CVE-2026-20230)
Cisco Unified Communications Manager's WebDialer service, when enabled, contains an improper-input-validation flaw that allows an unauthenticated remote attacker to conduct server-side request forgery (SSRF) attacks by sending crafted HTTP requests.…
Patched 2026-07-19 - CVE-2026-15409 network CRITICAL 10 KEV Ransomware EPSS 78%
SonicWall SMA1000 WorkPlace SSRF → Internal Erlang RPC Remote Code Execution (CVE-2026-15409)
The SMA1000 WorkPlace interface exposes a websocket-based remote-access proxy (wsproxy) that lets an authenticated remote-access session request a proxied connection to a destination host/port/service combination (e.g. SSH, TELNET). The proxy does not…
Patched 2026-07-15 - network HIGH
OpenSSH Forwarded-Agent Lock/Unlock State Confusion → Unauthorized PKCS#11 Provider Load (No CVE)
OpenSSH's ssh-agent supports being locked with a password, during which it is supposed to refuse essentially all requests — including the session-bind@openssh.com extension that a forwarded agent connection uses to record which remote session it belongs to.…
Unpatched 2026-07-12 - CVE-2022-26258 network CRITICAL 9.8 KEV EPSS 80%
D-Link DIR-820L `get_set.ccp` LAN Configuration OS Command Injection (CVE-2022-26258)
D-Link DIR-820L firmware 1.05B03 contains an OS command injection (CWE-78) in the router's /getset.ccp LAN-configuration handler. The lanHostCfgDeviceName1.1.1.0 parameter (submitted from the "Device Name" field on the lan.asp LAN setup page) is filtered by…
Unverified 2026-07-11 - network CRITICAL
XRING — XQUIC QPACK Ring Buffer Resize Underflow (Remote Unauthenticated DoS)
XRING is a remote, unauthenticated crash in XQUIC (Alibaba's QUIC/HTTP-3 library) triggered by fully spec-compliant QPACK dynamic-table encoder-stream instructions. A single incorrect variable in xqcringmemresize() (src/common/utils/ringmem/xqcringmem.c)…
Unpatched 2026-07-08 - CVE-2025-54322 network CRITICAL 10 EPSS 14%
XSpeeder SXZOS Pre-Auth eval() Remote Code Execution (CVE-2025-54322)
XSpeeder SXZOS firmware exposes a Django-based web endpoint that passes a base64-decoded, attacker-controlled chkid query parameter into Python's eval(). Because there is no authentication check on this endpoint and no sanitization of the decoded payload, an…
Unpatched 2026-07-06 - CVE-2025-13315 network CRITICAL 9.8 EPSS 33%
Twonky Server 8.5.2 Unauthenticated `/nmc/rpc/` Auth Bypass & Admin Credential Log Leak (CVE-2025-13315)
CVE-2025-13315 is a critical access-control flaw in Twonky Server 8.5.2 discovered by Rapid7: an earlier fix restricted unauthenticated access to the /rpc/ endpoint prefix, but the equivalent /nmc/rpc/ routing path was left unprotected, so privileged RPC…
Unpatched 2026-07-06 - CVE-2025-29384 network CRITICAL 9.8
Tenda AC9 `AdvSetMacMtuWan` Stack-Based Buffer Overflow (CVE-2025-29384)
CVE-2025-29384 is a critical stack-based buffer overflow in the Tenda AC9 router's web management interface, specifically in the handling of the wanMTU POST parameter sent to the /goform/AdvSetMacMtuWan endpoint. The root cause is a lack of bounds checking…
Unpatched 2026-07-06 - CVE-2025-62168 network CRITICAL 10 EPSS 63%
Squid Proxy Sensitive Header Leak via Error Page `mailto:` Diagnostic Block (CVE-2025-62168)
When Squid is configured with emailerrdata enabled (including in default configurations), it embeds diagnostic details about a failed request — including the original client's HTTP request headers — into the auto-generated error page it returns. Specifically,…
Patched 2026-07-06 - CVE-2025-11953 network CRITICAL 9.8 KEV EPSS 94%
React Native Community CLI Metro Dev Server `/open-url` OS Command Injection (CVE-2025-11953)
The Metro Development Server started by the React Native Community CLI binds to external network interfaces by default and exposes an /open-url HTTP endpoint (implemented by openURLMiddleware in @react-native-community/cli-server-api) that is intended to open…
Patched 2026-07-06 - CVE-2025-34299 network CRITICAL 9.8 EPSS 73%
Monsta FTP Pre-Authentication Remote Code Execution via Arbitrary File Upload (CVE-2025-34299)
Monsta FTP versions up to and including 2.11.2 contain a pre-authentication, unrestricted arbitrary file upload vulnerability (CWE-434) in the downloadFile action of its /mftp/application/api/api.php endpoint. The endpoint accepts a user-supplied FTP…
Patched 2026-07-06 - CVE-2025-52913 network CRITICAL 9.8
Mitel MiCollab Path Normalization Bypass to Internal Endpoints (CVE-2025-52913)
Mitel MiCollab fails to properly normalize URL paths before applying access-control checks on its NPM (Network Protocol Manager) web endpoints. By appending crafted traversal sequences such as ..;/..;/ after seemingly-legitimate, unauthenticated-facing…
Unverified 2026-07-06 - CVE-2025-37164 network CRITICAL 10 KEV EPSS 90%
HPE OneView `id-pools/executeCommand` OS Command Injection (CVE-2025-37164)
HPE OneView exposes a REST endpoint, /rest/id-pools/executeCommand, that accepts a JSON body containing a cmd field and executes it as an OS command on the appliance. The root cause is that the endpoint passes attacker-supplied input from the cmd field…
Unpatched 2026-07-06 - CVE-2025-66039 network CRITICAL 9.8
FreePBX Framework Module Authentication Bypass via Forged Authorization Header (CVE-2025-66039)
CVE-2025-66039 is a critical authentication bypass in the FreePBX framework module that occurs when the system's "Authorization Type" (AUTHTYPE) is configured to webserver — in this mode FreePBX trusts an externally-supplied Authorization header (intended for…
Patched 2026-07-06 - CVE-2025-64446 network CRITICAL 9.8 KEV EPSS 92%
FortiWeb `cgi-bin/fwbcgi` Path Traversal Authentication Bypass Leading to Rogue Admin Creation (CVE-2025-64446)
FortiWeb exposes an internal CGI handler (cgi-bin/fwbcgi) that is reachable through the authenticated cmdb REST API path by appending a relative path-traversal sequence (../) after a request to a nonexistent object (admin%3f). Because path handling for the…
Unverified 2026-07-06 - CVE-2025-59718 network CRITICAL 9.8 KEV EPSS 63%
FortiOS/FortiProxy/FortiSwitchManager/FortiWeb FortiCloud SSO Authentication Bypass Detection Tool (CVE-2025-59718)
CVE-2025-59718 is an improper verification of a cryptographic signature in Fortinet's FortiCloud SSO admin-login flow across FortiOS, FortiProxy, FortiSwitchManager, and FortiWeb, allowing authentication bypass when admin-forticloud-sso-login is enabled on a…
Patched 2026-07-06 - CVE-2025-63353 / GHSA-cg2x-c25f-6327 network CRITICAL 9.8
FiberHome HG6145F1 Predictable Default Wi-Fi PSK Derived from Broadcast SSID (CVE-2025-63353)
The FiberHome HG6145F1 GPON ONT broadcasts a factory-default SSID of the form fh<hexa>, where <hexa> is a six-character lowercase hex string. The factory-default WPA2 pre-shared key printed on the device label is a deterministic function of that same value:…
Patched 2026-07-06 - CVE-2025-60854 network CRITICAL 9.8
D-Link AX1500 SetDeviceSettings `DeviceName` OS Command Injection (CVE-2025-60854)
The D-Link AX1500 web management interface exposes a SetDeviceSettings SOAP action (reached via the /DHMAPI/ HNAP-style endpoint) that lets a client update the router's DeviceName. The vulnerable firmware function (identified in the binary as…
Patched 2026-07-06 - CVE-2025-11492 network CRITICAL 9.6
ConnectWise Automate Adversary-in-the-Middle Remote Code Execution (CVE-2025-11492)
The ConnectWise Automate RMM agent can be configured with an http:// fallback Server Address (observed as default/common configuration at multiple MSPs); an attacker with AiTM network position can force a fallback from HTTPS to HTTP, then serve a forged…
Patched 2026-07-06 - CVE-2025-20393 network CRITICAL 10 KEV EPSS 30%
Cisco AsyncOS Spam Quarantine (TCP/6025) Exposure & IOC Scanner (CVE-2025-20393)
CVE-2025-20393 is an unauthenticated remote code execution vulnerability in Cisco AsyncOS's Spam Quarantine service, which listens on TCP/6025. This repository provides a detection-only tool that (1) checks whether TCP/6025 is reachable on a target Secure…
Unverified 2026-07-06 - CVE-2025-20333 network CRITICAL 9.9 KEV EPSS 40%
Cisco ASA/FTD WebVPN File-Handler Heap Buffer Overflow Exposure Scanner (CVE-2025-20333)
CVE-2025-20333 is a critical heap-based buffer overflow in the WebVPN file-upload handler of Cisco Secure ASA and FTD devices, which can lead to remote code execution as root when successfully exploited (typically after first bypassing authentication via the…
Unverified 2026-07-06 - CVE-2025-55315 network CRITICAL 9.9 EPSS 66%
ASP.NET Core Kestrel HTTP Request Smuggling (CVE-2025-55315)
CVE-2025-55315 is an HTTP request-smuggling vulnerability in the Kestrel web server used by ASP.NET Core, caused by Kestrel's chunked-transfer-encoding parser accepting a lone \n in a chunk-size line where the HTTP/1.1 spec requires \r\n. When Kestrel sits…
Patched 2026-07-06 - CVE-2026-1459 network HIGH
Zyxel VMG3625-T50B Authenticated Command Injection to Root SSH Access (CVE-2026-1459)
The router's web management interface exposes a TR369Certificates CGI endpoint whose name parameter, used during a certificate "download" action, is passed unsanitized into a shell command executed as root. An authenticated administrator (or attacker with…
Unverified 2026-07-05 - CVE-2026-34474 network HIGH EPSS 25%
ZTE ZXHN H298A / H108N Router Unauthenticated Credential Disclosure (CVE-2026-34474)
CVE-2026-34474 is an unauthenticated information disclosure in the web management interface of ZTE ZXHN H298A and H108N router firmware. A crafted GET request to getpage.lua?pid=1000ÐCheat=1 returns HTML containing the live administrator password, WLAN…
Unverified 2026-07-05 - CVE-2026-34472 network CRITICAL
ZTE ZXHN H188A Unauthenticated Wizard Handler Credential Disclosure / Auth Bypass (CVE-2026-34472)
CVE-2026-34472 is an authentication bypass in ZTE ZXHN H188A V6 routers caused by unauthenticated access to pre-login "wizard" handlers. Root-path routing trusts attacker-controlled type/tag parameters, and the QuickSetupEnable gate that should block this…
Unverified 2026-07-05 - CVE-2026-34473 network HIGH
ZTE Router Unauthenticated Oversized-POST Denial of Service (CVE-2026-34473)
CVE-2026-34473 is an unauthenticated denial-of-service condition in ZTE H-series routers' web management interface, rooted in how the cgilua/post.lua pre-auth request-body parser handles oversized application/x-www-form-urlencoded POST bodies. Sending a…
Unverified 2026-07-05 - CVE-2026-25807 network CRITICAL
ZAI-Shell — Unauthenticated Remote Code Execution via P2P Terminal Sharing (CVE-2026-25807)
ZAI-Shell exposes a peer-to-peer terminal-sharing feature that listens on a TCP socket and accepts a simple JSON-line protocol (hello / command messages). When the host starts a sharing session with --no-ai (noaimode), commands received over this P2P channel…
Patched 2026-07-05 - CVE-2026-42568 / GHSA-cqh3-jg8p-336j network MEDIUM
YAMCS LdapAuthModule LDAP Injection Authentication Bypass (CVE-2026-42568)
YAMCS's LdapAuthModule builds LDAP search filters by directly substituting the user-supplied username into a filter template (e.g. (uid={0})) without RFC 4515 escaping. An attacker can supply LDAP metacharacters in the username field to alter the filter's…
Patched 2026-07-05 - CVE-2026-38698 network CRITICAL
Wyze Cam Pan v3 / TUTK SDK — tutk_packet_alloc Heap Overflow (CVE-2026-38698)
The tutkpacketalloc function inside the TUTK SDK's tutkavserver component, used by Wyze Cam Pan v3 and other TUTK-integrated IoT cameras, allocates a buffer for incoming AV packets based on an attacker-influenced size field without adequate bounds validation.…
Unverified 2026-07-05 - CVE-2026-24294 network CRITICAL
Windows Server 2025 Local NTLM Reflection LPE via SMB Arbitrary Port + PetitPotam (CVE-2026-24294)
Windows 11 24H2 / Server 2025 introduced an SMB client capability allowing connections to arbitrary TCP ports via net use \\host\share /tcpport:PORT. Combined with SMB2 session multiplexing, this enables a local NTLM reflection attack: a low-privileged local…
Patched 2026-07-05 - CVE-2026-26128 network CRITICAL
Windows Kerberos Reflection via Unicode SPN Normalization Bypass (CVE-2026-26128)
CVE-2026-26128 is a Kerberos relay vulnerability rooted in a mismatch between how two different Windows components normalize Unicode characters when resolving Service Principal Names. The client-side DnsCache service uses CompareStringW with NORMIGNORECASE,…
Unverified 2026-07-05 - CVE-2026-33824 network CRITICAL EPSS 56%
Windows ikeext.dll IKEv2 Double-Free Remote Kernel Exploit — CVE-2026-33824
This repository is an in-progress C/C++ exploit prototype targeting a double-free vulnerability in Windows' ikeext.dll, the kernel driver that handles IKEv2 IPsec negotiation over UDP port 500. The exploit constructs and sends fragmented (SKF) IKEv2 packets…
Patched 2026-07-05 - CVE-2026-36522 network CRITICAL 9.1
Unauthenticated NaN Injection via MAVLink PARAM_SET in ArduPilot ArduPlane (CVE-2026-36522)
ArduPilot ArduPlane's GCSMAVLink::handleparamset() does not validate that a parameter value supplied via a MAVLink PARAMSET message is a well-formed floating-point number. An unauthenticated party able to send MAVLink messages to the vehicle can inject a NaN…
Unverified 2026-07-05 - CVE-2026-0651 network CRITICAL
TP-Link Tapo C260 Unauthenticated-to-Root RCE Chain — CVE-2026-0651
This PoC chains three vulnerabilities in the TP-Link Tapo C260 camera to go from unauthenticated (or guest-level) access to root command execution. First, a path traversal flaw in the HTTP GET handler allows arbitrary local file disclosure. Second, a…
Unverified 2026-07-05 - CVE-2026-11834 network CRITICAL
TP-Link DHCP Option 66 Unauthenticated RCE — CVE-2026-11834
TP-Link router firmware processes DHCP Option 66 ("TFTP Server Name") from a lease it acquires on its WAN interface by concatenating the value unsanitized into a tftp shell command inside libcmm.so, which is ultimately passed to system() via utilexecSystem().…
Unverified 2026-07-05 - CVE-2026-8697 network CRITICAL 9.3
TP-Link Archer C64 Web UI Rate-Limit Bypass via Residual Debug SSH Service (CVE-2026-8697)
The TP-Link Archer C64 exposes a residual debug SSH service (port 22) that does not grant a shell — it simply closes the connection once a password is entered — but validates the password against the same credential used by the router's web admin interface,…
Unverified 2026-07-05 - CVE-2026-11499 network HIGH
Tenda HG7/HG9/HG10 Router Stack-Based Buffer Overflow — CVE-2026-11499
CVE-2026-11499 is a stack-based buffer overflow (CWE-121) in the web-management formDOMAINBLK handler of Tenda HG7/HG9/HG10 router firmware. The vulnerable code path copies the attacker-supplied blkDomain form parameter into a fixed-size stack buffer without…
Unverified 2026-07-05 - CVE-2026-38426 network CRITICAL 9.8
Tasmota fetch_jpg() strcpy() Buffer Overflow in boundary[40] (CVE-2026-38426)
The fetchjpg() function's initial-connection handling (case 0) in Tasmota's scripter driver extracts the MJPEG multipart boundary string from the HTTP Content-Type response header and copies it into a fixed 40-byte boundary[40] field of the JPGTASK struct…
Patched 2026-07-05 - CVE-2026-38427 network CRITICAL 9.8
Tasmota fetch_jpg() Integer Wraparound to Heap Corruption (CVE-2026-38427)
When fetching subsequent MJPEG frames (case 2) in Tasmota's scripter driver, fetchjpg() reads the Content-Length header value via atoi() into a uint16t variable. Values above 65535 silently wrap around (e.g. 65537 becomes 1), causing the device to allocate a…
Patched 2026-07-05 - CVE-2026-38422 network CRITICAL 9.8
Tasmota fetch_jpg() Combined Buffer Overflow RCE Chain (CVE-2026-38422)
Tasmota's scripter driver (xdrv10scripter.ino) implements an MJPEG client via fetchjpg() that contains two compounding memory-corruption bugs: a strcpy() overflow of a fixed 40-byte boundary[] buffer when parsing the Content-Type boundary string…
Patched 2026-07-05 - CVE-2026-35333 network MEDIUM
strongSwan RADIUS Attribute-Iterator Pre-Auth Infinite Loop / Remote DoS (CVE-2026-35333)
strongSwan's attributeenumerate() in src/libradius/radiusmessage.c accepts RADIUS attributes whose length byte is smaller than sizeof(rattrt) (2 bytes). When length == 0, the remaining-data counter underflows to a huge value and the loop's decrement condition…
Unverified 2026-07-05 - CVE-2026-35330 network HIGH
strongSwan EAP-SIM/EAP-AKA Pre-Auth Heap Buffer Overflow via Integer Underflow (CVE-2026-35330)
strongSwan's parseattributes() in src/libsimaka/simakamessage.c reads TLV attribute headers whose length byte counts 4-byte words. For the ATRAND/ATENCRDATA branches, a crafted small length value causes an integer underflow in the computed remaining-data…
Unverified 2026-07-05 - CVE-2026-42096 network CRITICAL
Sparx Enterprise Architect / Pro Cloud Server Unauthenticated Binary-Protocol SQL Injection (CVE-2026-42096)
Sparx Pro Cloud Server exposes a SparxCloudLink.sseap endpoint that accepts a proprietary binary protocol used by the Enterprise Architect desktop client to query the underlying repository database. Commands (including raw SQL query strings) are obfuscated…
Unverified 2026-07-05 - CVE-2026-4112 network HIGH 7.2
SonicWall SMA 8200v Cross-Parameter Blind SQL Injection to Root (CVE-2026-4112)
The SonicWall SMA 8200v management console contains a post-authentication blind SQL injection in the /activeUsers.action endpoint, reachable by any authenticated user regardless of role — including a read-only monitoring account. The application's safeParam()…
Unverified 2026-07-05 - CVE-2026-29781 network HIGH
Sliver C2 Server mTLS Nil-Pointer Panic / Infrastructure Kill-Switch — CVE-2026-29781
Sliver C2's transport-layer protobuf handlers (mTLS, WireGuard, DNS) lack consistent nil-pointer validation and lack a recover() mechanism around packet processing. A party in possession of a captured implant's mTLS certificate, private key, and Age secret…
Unverified 2026-07-05 - CVE-2026-4480 network CRITICAL EPSS 14%
Samba spoolss Print Job Command Injection RCE (CVE-2026-4480)
This PoC targets a flaw in Samba's spoolss print spooler RPC interface where a submitted print job's document name/content is not safely handled, allowing an attacker who can open a writable printer/share to inject a shell command that gets executed on the…
Patched 2026-07-05 - CVE-2026-36355 network CRITICAL
Realtek rtl819x Jungle SDK Unauthenticated Kernel Memory R/W via Debug IOCTLs (CVE-2026-36355)
The rtl8192cd Wi-Fi kernel driver in Realtek's out-of-tree rtl819x "Jungle SDK" exposes two IOCTLs — writemem (0x89F5) and readmem (0x89F6) — with no access-control checks. These debug handlers are gated only by a macro (IOCTLDEBUGCMD) that is defined…
Unverified 2026-07-05 - CVE-2026-42167 network HIGH 8.1
ProFTPD mod_sql Pre-Auth SQL Injection Leading to RCE (CVE-2026-42167)
CVE-2026-42167 is a pre-authentication SQL injection in ProFTPD's modsql logging support. The module's isescapedtext() sanitizer fails to properly neutralize input used to populate logging variables (such as %U), which are substituted into SQL statements…
Patched 2026-07-05 - CVE-2026-32945 network MEDIUM
PJSIP DNS Compression Pointer Heap Out-of-Bounds Read (CVE-2026-32945)
getnamelen() and getname() in pjproject's pjlib-util/src/pjlib-util/dns.c read a 2-byte DNS message-compression pointer via pjmemcpy(&offset, p, 2) without verifying that both bytes fall within the received packet buffer. If the compression-pointer marker…
Patched 2026-07-05 - CVE-2026-25994 network HIGH
PJSIP / PJNATH ICE Session Stack Buffer Overflow via SDP ice-ufrag (CVE-2026-25994)
CVE-2026-25994 is a stack-based buffer overflow in PJNATH's ICE (Interactive Connectivity Establishment) session handling, specifically in pjicesesscreatechecklist() in pjnath/src/pjnath/icesession.c. When constructing the ICE username, the code copies the…
Patched 2026-07-05 - CVE-2026-6664 network HIGH
PgBouncer SASL Length Field Integer Overflow Crash — CVE-2026-6664
PgBouncer's mbufgetbytes() bounds check (lib/usual/mbuf.h) computes buf->readpos + len > buf->writepos using 32-bit unsigned arithmetic, which wraps around when a client supplies a very large length value in a SASLInitialResponse ('p') message, silently…
Patched 2026-07-05 - CVE-2026-28466 network CRITICAL
OpenClaw Gateway WebSocket Authentication Bypass RCE — CVE-2026-28466
OpenClaw exposes a WebSocket control-plane gateway (/ws) used to manage connected nodes/agents. The gateway's connect handshake accepts a client-supplied auth token and role/scope set without properly validating that the presented token is bound to the…
Patched 2026-07-05 - CVE-2026-41285 network HIGH
OpenBSD slaacd/rad Infinite Loop via Malformed ND Option (CVE-2026-41285)
slaacd and rad each contain their own userland parser for ICMPv6 Neighbor Discovery (ND) options, separate from the kernel's already-correct nd6options() validation. Their parsing loop computes optlen = ndoptlen 8 - 2, and when an attacker sends an ND option…
Patched 2026-07-05 - CVE-2026-24207 network CRITICAL 9.8
NVIDIA Triton Inference Server SageMaker Auth Bypass to Unauthenticated RCE (CVE-2026-24207)
NVIDIA Triton Inference Server exposes separate HTTP endpoints for SageMaker and Vertex AI multi-model integration. These endpoints bypass the operator-configured --http-restricted-api access control, meaning the model-management surface…
Patched 2026-07-05 - CVE-2026-1337 network LOW
Neo4j Bolt Transaction Metadata Log Injection (CVE-2026-1337)
Neo4j writes the transaction metadata field supplied over the Bolt protocol directly into query.log without escaping control characters such as newlines. An authenticated user can therefore embed a crafted metadata value containing full fake log lines, which…
Unverified 2026-07-05 - CVE-2026-6992 network HIGH
MR9600 Router Bluetooth/JNAP Management Interface RCE Injection (CVE-2026-6992)
MR9600 routers with Bluetooth management capability expose a vulnerable JNAP request path that allows command injection via the Bluetooth PIN configuration flow, enabling an attacker to execute arbitrary commands on the router. The PoC reverses the original…
Unverified 2026-07-05 - CVE-2026-36356 network CRITICAL EPSS 14%
MeiG Smart FORGE_SLT711 GoAhead Unauthenticated OS Command Injection (CVE-2026-36356)
The GoAhead web server bundled with MeiG Smart FORGESLT711 4G LTE CPE devices exposes an unauthenticated HTTP endpoint, /action/SetRemoteAccessCfg, that interpolates user-controlled JSON input into a shell command without sanitization. A single…
Unverified 2026-07-05 - CVE-2026-3494 network MEDIUM
MariaDB server_audit Plugin Logging Bypass via Inline Comments (CVE-2026-3494)
CVE-2026-3494 is a logging-omission regression in MariaDB's serveraudit plugin. When serveraudit is configured with filters such as QUERYDCL, QUERYDDL, and QUERYDML, certain queries containing inline # or -- comments — including queries that trigger error…
Patched 2026-07-05 - CVE-2026-8836 network CRITICAL 9.8
lwIP SNMPv3 USM Stack-Based Buffer Overflow (CVE-2026-8836)
lwIP's SNMPv3 User-based Security Model (USM) handler contains a stack-based buffer overflow in snmpparseinboundframe(). A commented-out bounds check combined with an incorrect buffer-size parameter passed to snmpasn1decraw() allows an oversized…
Patched 2026-07-05 - CVE-2026-54420 network HIGH 8.5 KEV
LiteSpeed cPanel/WHM Plugin Symlink Privilege Escalation — CVE-2026-54420
LiteSpeed's cPanel and WHM plugins mishandle user-supplied symbolic links on shared hosting servers isolated with CloudLinux/CageFS. A tenant with FTP or web shell access to their own account can create a symlink (via SITE SYMLINK, rename-based tricks, or…
Unverified 2026-07-05 - CVE-2026-23398 network HIGH
Linux Kernel ICMP Fragmentation-Needed NULL Pointer Dereference (CVE-2026-23398)
CVE-2026-23398 is a NULL pointer dereference in the Linux kernel's ICMP handling path, reachable when a host has net.ipv4.ipnopmtudisc set to 3 (a hardened Path MTU Discovery mode) and receives a crafted ICMP "Fragmentation Needed" (type 3, code 4) packet.…
Patched 2026-07-05 - CVE-2026-1281, CVE-2026-1340 network CRITICAL KEV EPSS 82%
Ivanti EPMM Pre-Auth RCE via Bash Arithmetic Expansion (CVE-2026-1281 / CVE-2026-1340)
This is a self-contained Docker/Nginx lab that reproduces the vulnerable Bash logic behind Ivanti EPMM's pre-auth RCE (as documented by watchTowr Labs). The map-appstore-url CGI script parses comma-separated key=value pairs from a crafted appstore URL in a…
Patched 2026-07-05 - CVE-2026-23813 network CRITICAL 9.8
HPE Aruba AOS-CX Pre-Auth REST API Bypass via nginx Version Smuggling (CVE-2026-23813)
AOS-CX fronts its management REST API with nginx, which uses an over-permissive regular expression to route requests by API version/login path. By smuggling a login-flavored token into the request path, an unauthenticated attacker can reach REST endpoints…
Patched 2026-07-05 - CVE-2026-33555 network HIGH
HAProxy HTTP/3 (QUIC) Standalone FIN Body Validation Bypass Leading to Request Smuggling — CVE-2026-33555
HAProxy's HTTP/3 frontend does not validate that a request's declared Content-Length matches the number of body bytes actually delivered over the QUIC stream before the stream is closed (a "standalone FIN"). When HAProxy translates such a malformed HTTP/3…
Patched 2026-07-05 - CVE-2026-33186 network HIGH
gRPC-Go RBAC Authorization Bypass via Missing Leading Slash in `:path` (CVE-2026-33186)
gRPC-Go's authz package implements RBAC using deny/allow rules matched against the HTTP/2 :path pseudo-header (e.g. /Service/Method). The HTTP/2 server transport stores the raw, pre-normalization :path value in context, but the routing layer (handleStream)…
Patched 2026-07-05 - CVE-2026-6807 network HIGH
GRASSMARLIN XML External Entity (XXE) Out-of-Band File Exfiltration (CVE-2026-6807)
GRASSMARLIN's handling of XML files ingested when opening stored sessions is vulnerable to XML External Entity (XXE) injection. A crafted session XML referencing an external DTD/entity allows out-of-band exfiltration of arbitrary local files from the…
Unverified 2026-07-05 - CVE-2026-32746 network CRITICAL 9.8 EPSS 24%
GNU InetUtils telnetd LINEMODE SLC Pre-Auth Buffer Overflow (CVE-2026-32746)
GNU InetUtils telnetd's addslc() function in telnetd/slc.c appends 3 bytes per SLC (Set Local Characters) triplet into a fixed 108-byte buffer (slcbuf) with no bounds checking. During telnet option negotiation, before any login prompt is shown, an…
Unverified 2026-07-05 - CVE-2026-39808 network CRITICAL 9.8 KEV EPSS 91%
FortiSandbox 4.4.0-4.4.8 — OS Command Injection via tracer-behavior Endpoint (CVE-2026-39808)
FortiSandbox versions 4.4.0 through 4.4.8 contain a critical OS command injection vulnerability in the tracer-behavior API endpoint (job-detail/tracer-behavior), reachable via the jid request parameter. Improper neutralization of special shell characters…
Unverified 2026-07-05 - CVE-2026-25089 network CRITICAL 9.8 KEV EPSS 74%
Fortinet FortiSandbox "Start VNC" OS Command Injection (CVE-2026-25089)
FortiSandbox's Web UI "start VNC" feature passes a caller-supplied virtual machine name into an OS command without proper neutralization of shell metacharacters, allowing an unauthenticated attacker to inject arbitrary commands executed on the underlying…
Patched 2026-07-05 - CVE-2026-5172 network INFO
dnsmasq extract_addresses() RDLEN/RDATA Buffer Overflow — CVE-2026-5172
The PoC targets extractaddresses() in dnsmasq, which parses resource records (RRs) returned by an upstream DNS server. The function is reported to trust the RR's declared RDLENGTH field without properly validating it against the actual RDATA bytes present in…
Patched 2026-07-05 - CVE-2026-4893 network MEDIUM
dnsmasq EDNS Client Subnet (ECS) Response Validation Bypass (CVE-2026-4893)
This PoC demonstrates that dnsmasq, when configured with EDNS Client Subnet (ECS, RFC 7871) via add-subnet, will accept an upstream DNS response carrying an ECS option whose subnet does not match the subnet dnsmasq originally sent in the query. The included…
Patched 2026-07-05 - CVE-2026-3805 network HIGH
curl SMB Connection-Reuse Use-After-Free (CVE-2026-3805)
libcurl's SMB protocol handler stores a request-scoped req->path pointer that points into memory owned by a temporary "needle" connection object used during connection-cache lookup (smbc->share). When a second SMB transfer to the same server reuses an…
Patched 2026-07-05 - CVE-2026-20182 network CRITICAL 10 KEV EPSS 90%
Cisco Catalyst SD-WAN Peering Authentication Bypass — CVE-2026-20182
Cisco Catalyst SD-WAN Controller and Manager rely on a peering authentication handshake between fabric control-plane devices over DTLS on UDP port 12346, handled by the vdaemon process. A flaw in how this control-connection handshake enforces peering…
Patched 2026-07-05 - CVE-2026-49943 network HIGH 3.1
BIRD/BIRD2 BGP AS_PATH Mask Matching Stack Buffer Overflow (CVE-2026-49943)
This repository documents a stack-based buffer overflow in BIRD's BGP ASPATH mask matching code (aspathmatch() in nest/a-path.c). The function uses a fixed-size stack array of 2048 + 1 pmpos entries, but parsepath() expands ASPATH segments from a received BGP…
Patched 2026-07-05 - CVE-2026-7473 network MEDIUM 5.8 KEV
Arista EOS Tunnel Decapsulation Protocol-Type Bypass — CVE-2026-7473
Arista EOS switches configured as a tunnel decapsulation endpoint (for VXLAN, GRE, or generic ip decap-group/GUE/IP-in-IP profiles) incorrectly decapsulate and forward tunneled packets of an unexpected/non-configured protocol type as long as the outer…
Unverified 2026-07-05 - CVE-2026-42779 network CRITICAL 9.8
Apache MINA acceptMatchers Deserialization Filter Bypass to RCE (CVE-2026-42779)
CVE-2026-42779 is a deserialization filter bypass in Apache MINA's AbstractIoBuffer.resolveClass(). Applications configure an acceptMatchers allowlist to restrict which Java classes ObjectSerializationCodecFactory may deserialize, but the allowlist check is…
Patched 2026-07-05 - CVE-2026-49975 network HIGH EPSS 28%
Apache HTTP Server HTTP/2 HPACK Cookie-Merging Memory Bomb (CVE-2026-49975)
CVE-2026-49975 is a denial-of-service vulnerability in Apache HTTP Server's HTTP/2 request handling. A small HPACK-encoded HTTP/2 header block can reference the HPACK dynamic-table entry for the cookie header many times (up to the request field limit), which…
Unverified 2026-07-05 - CVE-2026-34197 network CRITICAL KEV EPSS 97%
Apache ActiveMQ Classic Jolokia addNetworkConnector Xbean Spring-XML RCE (CVE-2026-34197)
Apache ActiveMQ Classic exposes broker management via Jolokia, a JMX-over-HTTP bridge. The BrokerView.addNetworkConnector(uri) MBean operation accepts a discovery URI that can specify an inner vm:// transport with a brokerConfig=xbean:<url> parameter. This…
Patched 2026-07-05 - CVE-2026-6042 network HIGH 7.5
Algorithmic Complexity DoS in musl libc `iconv` GB18030 Decoder — CVE-2026-6042
musl libc's GB18030 4-byte decoder (src/locale/iconv.c) contains a gap-skipping loop that, for each decoded character, iterates the entire 23,940-entry gb18030[126][190] lookup table to resolve a linear index to a Unicode codepoint. A crafted 4-byte sequence…
Unverified 2026-07-05 - None assigned as of 2026-07-04 network HIGH
PostgreSQL Referential-Integrity Owner-Switched Implicit Cast RCE
This PoC demonstrates that PostgreSQL's referential-integrity (RI) enforcement for foreign keys switches its effective role to the referenced table's owner before invoking any implicit cast needed to compare the foreign-key value against the primary-key type.…
Unverified 2026-07-04 - None assigned as of 2026-07-03 network HIGH
RustDesk Relay Session Downgrade and FileTransfer Authorization Scope Bypass
This entry covers two related but distinct RustDesk findings. First, RustDesk's client can fail open on secure-session setup: when the signed peer key material from the rendezvous/relay path is missing or invalid, the client requests a non-secure relay and…
Unverified 2026-07-03 - None assigned as of 2026-07-03 network CRITICAL
Redis Vector Set Duplicate HNSW Node ID RCE
Redis Vector Set RDB/RESTORE deserialization accepts serialized HNSW graph nodes that reuse the same node ID, but the ID-lookup table only tracks one node per ID while the element dictionary tracks nodes by name, so link validation ends up trusting IDs…
Unverified 2026-07-03 - None assigned as of 2026-07-03 network HIGH
OpenVPN Connect Server-Pushed Option Current-User Command Execution
A malicious OpenVPN server can push an echo option to a connected OpenVPN Connect for Windows client that decodes into the internal script.win.user.disconnect script key. OpenVPN Connect then executes that pushed command when the client disconnects, even…
Unverified 2026-07-03 - None assigned as of 2026-07-03 network LOW
Nmap IPv6 Extension-Header Length Wrap
The Nmap IPv6 extension-header parser in libnetutil/netutil.cc advances a payload pointer by an attacker-declared extension-header length without first checking that the advanced pointer stays within the bounds of the captured packet. When a crafted,…
Unverified 2026-07-03 - None assigned as of 2026-07-03 network HIGH
nghttpx HTTP/1.1 Upgrade Request Body Response Queue Poisoning
nghttpx, the reverse proxy shipped with nghttp2, incorrectly accepts an HTTP/1.1 Upgrade request that also carries a Content-Length header, then forwards both the Upgrade headers and the body bytes unmodified to a keep-alive HTTP/1.1 backend connection. If…
Patched 2026-07-03 - CVE-2026-55200 network CRITICAL
libssh2 Unchecked SSH packet_length Integer Wrap to RCE (CVE-2026-55200)
CVE-2026-55200 is an unchecked packetlength condition in libssh2's ssh2transportread() transport-parsing path. The vulnerable code accepts an attacker-controlled decrypted SSH packetlength field and only rejects values less than 1, then computes an allocation…
Patched 2026-07-03 - None assigned as of 2026-07-03 network CRITICAL
libssh2 Publickey Subsystem List Parser Heap Corruption to Code Execution
libssh2publickeylistfetch() parses a stream of publickey-subsystem response packets and grows an array of libssh2publickeylist entries as responses arrive, but the parser has two distinct memory-safety defects depending on target architecture. On 32-bit…
Unverified 2026-07-03 - CVE-2026-35616 network CRITICAL 9.1 KEV EPSS 89%
Fortinet FortiClient EMS Pre-Auth Bypass — "FortiBleed" (CVE-2026-35616)
CVE-2026-35616 is a pre-authentication bypass in Fortinet FortiClient EMS's certificate-chain authentication handler (certchainauth.py), which trusts the X-SSL-CLIENT-VERIFY header directly without performing real cryptographic validation of the presented…
Patched 2026-07-03 - None assigned as of 2026-07-03 network MEDIUM
curl SMTP EXPN Recipient CRLF Command Injection
Stock curl does not reject CR/LF sequences in the recipient operand used with SMTP EXPN/VRFY custom requests (CURLOPTMAILRCPT), allowing an attacker who controls that operand to inject arbitrary additional SMTP protocol lines into the same authenticated…
Unverified 2026-07-03 - CVE-2026-8451 network HIGH 7.5 EPSS 16%
Citrix NetScaler ADC/Gateway Pre-Auth SAML Memory Overread — "CitrixBleed"-style Leak (CVE-2026-8451)
CVE-2026-8451 is a pre-authentication out-of-bounds memory read in Citrix NetScaler ADC/Gateway's SAML request parser, in the same vulnerability class as the infamous 2023 "CitrixBleed" (CVE-2023-4966). By posting a specially-sized, malformed SAMLRequest to…
Unverified 2026-07-03 - None assigned as of 2026-07-03 network HIGH
c-ares TCP ares_getaddrinfo() Use-After-Free Code Execution
c-ares's aresgetaddrinfo() path over DNS-over-TCP with EDNS enabled contains a use-after-free reachable when a malicious or compromised DNS server sends two responses for the same query ID in a single TCP read — the first a FORMERR without OPT data…
Unverified 2026-07-03 - CVE-2026-47729 network MEDIUM
Squidbleed — Squid Proxy FTP Gateway Out-of-Bounds Heap Read (CVE-2026-47729)
CVE-2026-47729, dubbed "Squidbleed," is an out-of-bounds heap read in Squid Proxy's FTP gateway and FTP directory-listing parser. The bug stems from legacy FTP parsing logic (originally written in 1997 for NetWare-style listings) in FtpGateway.cc, where…
Patched 2026-07-01 - CVE-2026-20230 network CRITICAL 8.6 KEV EPSS 83%
Cisco Unified CM WebDialer SSRF to Arbitrary File Write / RCE (CVE-2026-20230)
CVE-2026-20230 is a critical server-side request forgery vulnerability in Cisco Unified CM / Unified CM SME caused by improper input validation of HTTP requests processed by the WebDialer component. A remote unauthenticated attacker can chain unauthenticated…
Unverified 2026-07-01 - CVE-2026-20262 network MEDIUM 6.5 KEV EPSS 28%
Cisco Catalyst SD-WAN Manager Arbitrary File Write (CVE-2026-20262)
CVE-2026-20262 is an authenticated remote arbitrary file write vulnerability in the web UI of Cisco Catalyst SD-WAN Manager. Improper validation of user-supplied input during a file upload process enables path traversal, letting an authenticated attacker…
Unverified 2026-07-01 - CVE-2026-55200 network CRITICAL 9.8
libssh2 SSH Packet Length OOB Heap Write / Unauthenticated RCE (CVE-2026-55200)
CVE-2026-55200 is a critical heap out-of-bounds write in libssh2's SSH transport layer (ssh2transportread() in src/transport.c). The function validates that packetlength is greater than zero but performs no upper-bound check, allowing an attacker-controlled…
Patched 2026-06-30 - CVE-2026-8932 network LOW
libcurl mTLS Connection Reuse Authentication Bypass (CVE-2026-8932)
CVE-2026-8932 is a Low-severity authentication bypass in libcurl's TLS connection reuse logic. Certain mTLS private-key configuration parameters (key file path, key type, key password) were omitted from the connection-matching comparison performed when…
Patched 2026-06-30 - CVE-2026-24061 network CRITICAL 9.8 KEV EPSS 98%
GNU Inetutils telnetd Unauthenticated Root RCE via NEW-ENVIRON (CVE-2026-24061)
CVE-2026-24061 is a critical authentication bypass in GNU Inetutils telnetd that grants an unauthenticated network attacker an immediate root shell. The NEW-ENVIRON Telnet option handler passes the USER environment variable unsanitised to /bin/login. Setting…
Patched 2026-06-30 - CVE-2026-12485 network CRITICAL 10
GeoVision GV-I/O Box 4E DVRSearch Unauthenticated Stack Buffer Overflow RCE (CVE-2026-12485)
CVE-2026-12485 is a CVSS 10.0 unauthenticated stack-based buffer overflow in the GeoVision GV-I/O Box 4E, a Linux-based smart I/O device used in physical security and building automation. The DVRSearch service listens on UDP port 10001 and handles CMDIPSET…
Patched 2026-06-30 - CVE-2026-34908, CVE-2026-34909, CVE-2026-34910 network CRITICAL 10 KEV EPSS 62%
Ubiquiti UniFi OS Unauthenticated RCE Chain (CVE-2026-34908 / CVE-2026-34909 / CVE-2026-34910)
A three-CVE unauthenticated RCE chain in Ubiquiti UniFi OS Server ≤ 5.0.6 allows a remote attacker to achieve root-level command execution with no credentials. CVE-2026-34908 and CVE-2026-34909 (improper access control + path traversal) are chained to bypass…
Patched 2026-06-28 - CVE-2026-10520, CVE-2026-10523 network CRITICAL 10 KEV EPSS 100%
Ivanti Sentry Pre-Auth RCE + Auth Bypass (CVE-2026-10520 / CVE-2026-10523)
Two critical vulnerabilities in Ivanti Sentry enable unauthenticated root-level RCE and arbitrary admin account creation. CVE-2026-10520 is an OS command injection in the MICS API at /mics/api/v2/sentry/mics-config/handleMessage (CVSS 10.0). CVE-2026-10523 is…
Patched 2026-06-28 - CVE-2026-20245 network HIGH 7.8 KEV EPSS 25%
Cisco Catalyst SD-WAN Manager Privilege Escalation (CVE-2026-20245)
CVE-2026-20245 is the seventh Cisco SD-WAN zero-day exploited in 2026. An authenticated attacker with netadmin privileges on Cisco Catalyst SD-WAN Manager can upload a specially crafted file to the CLI subsystem, triggering insufficient input validation and…
Unpatched 2026-06-28 - CVE-2026-50751 network CRITICAL 9.3 KEV Ransomware EPSS 83%
Check Point Remote Access VPN IKEv1 Auth Bypass (CVE-2026-50751)
CVE-2026-50751 is a critical authentication bypass in Check Point Remote Access VPN affecting gateways configured for the legacy IKEv1 protocol. A remote unauthenticated attacker can complete the deprecated IKEv1 phase-1 exchange and be authenticated as a…
Patched 2026-06-28 - CVE-2026-41089 network CRITICAL 9.8 EPSS 80%
Netlogon CLDAP Stack Buffer Overflow (CVE-2026-41089)
This PoC targets CVE-2026-41089, a stack-based buffer overflow in the Windows Netlogon CLDAP handling path. A crafted UDP/389 CLDAP ping containing an oversized User value can overrun a stack buffer in the LSASS/Netlogon flow and crash the domain controller.…
Patched 2026-06-04 - N/A network CRITICAL
TossUp — TerraMaster TOS Unauthenticated Redis Root RCE + NFS LPE
TossUp is a pair of bugs against TerraMaster TOS NAS devices. The primary issue is that Redis 4.0.10 runs as root and listens on 0.0.0.0:6379 with no authentication — despite /etc/redis.conf containing bind 127.0.0.1, the init script starts Redis as…
Unpatched 2026-05-18 - CVE-2025-0282 network CRITICAL 9 KEV Ransomware EPSS 100%
Ivanti Connect Secure Pre-Auth RCE (Stack Overflow)
CVE-2025-0282 is a pre-authentication stack-based buffer overflow in the IFT (IF-T) TLS protocol handling code of Ivanti Connect Secure VPN appliances. Discovered and disclosed by Sina Kheirkhah of watchTowr Labs, this zero-day was confirmed by Mandiant as…
Unverified 2026-05-17 - CVE-2024-47575 network CRITICAL 9.8 KEV EPSS 95%
Fortinet FortiManager FortiJump Unauthenticated RCE (CVE-2024-47575)
CVE-2024-47575 (FortiJump) is a missing-authentication flaw in FortiManager's fgfmd daemon that lets a remote unauthenticated attacker execute arbitrary commands. Public exploit code demonstrates vulnerability detection and command execution primitives over…
Unverified 2026-05-17 - CVE-2025-59718, CVE-2025-59719 network CRITICAL 9.8 KEV EPSS 63%
Fortinet FortiCloud SSO Authentication Bypass
CVE-2025-59718 and CVE-2025-59719 are closely related authentication-bypass vulnerabilities (CWE-347: Improper Verification of Cryptographic Signature) in Fortinet products that use the FortiCloud SSO login feature. Both were disclosed by Fortinet on 9…
Unverified 2026-05-17 - CVE-2025-32433 network CRITICAL 10 KEV EPSS 99%
Erlang/OTP SSH Pre-Auth RCE - CVE-2025-32433
CVE-2025-32433 is a critical pre-authentication remote code execution vulnerability in the Erlang/OTP SSH server with a CVSS score of 10.0. An attacker with network access to any service built on Erlang/OTP's SSH daemon can execute arbitrary OS commands…
Patched 2026-05-17 - CVE-2024-37079 network CRITICAL 9.8 KEV EPSS 22%
VMware vCenter Server DCE/RPC Heap Overflow RCE (CVE-2024-37079)
CVE-2024-37079 is a critical heap overflow condition in a vCenter Server DCE/RPC network-handling path. A crafted network packet can trigger memory corruption pre-authentication and potentially lead to remote code execution. Public reporting indicates patch…
Patched 2026-05-16 - CVE-2024-37085 network MEDIUM 6.8 KEV Ransomware EPSS 26%
VMware ESXi Active Directory Authentication Bypass (CVE-2024-37085)
CVE-2024-37085 is an authentication bypass in domain-joined VMware ESXi environments where AD group membership manipulation can grant administrator-level ESXi access without valid local ESXi credentials. Public reporting links this issue to real-world…
Patched 2026-05-16 - CVE-2024-6387 network HIGH 8.1 EPSS 100%
OpenSSH regreSSHion Signal-Handler Race Unauthenticated RCE (CVE-2024-6387)
CVE-2024-6387 (regreSSHion) is a signal-handler race condition in OpenSSH sshd that reintroduced a previously fixed bug class and can allow unauthenticated remote code execution as root on glibc-based Linux systems. The issue is triggered around…
Patched 2026-05-16 - CVE-2024-49113 network CRITICAL EPSS 83%
LDAP Nightmare — Windows LDAP Client RCE/DoS (CVE-2024-49113)
LDAP Nightmare is a public PoC for CVE-2024-49113, a critical vulnerability in Windows LDAP client behavior that can be reached through Netlogon workflow interactions. The PoC starts a malicious LDAP service and triggers victim-side LDAP resolution via…
Patched 2026-05-15 - CVE-2021-31166 network CRITICAL 9.8 KEV EPSS 100%
HTTP Protocol Stack Remote Code Execution Vulnerability (CVE-2021-31166)
CVE-2021-31166 is a remote use-after-free vulnerability in the Windows HTTP Protocol Stack (http.sys) that is reachable via crafted HTTP headers. The public PoC sends a malformed Accept-Encoding header to trigger unsafe list handling in the kernel HTTP parser…
Patched 2026-05-15 - CVE-2023-45866 network HIGH 8.8
BlueDucky — Unauthenticated Peering Leading to Code Execution (CVE-2023-45866)
BlueDucky is a practical PoC implementation for CVE-2023-45866. It automates Bluetooth device discovery/selection and then emulates HID keyboard input to inject attacker-controlled DuckyScript payloads on vulnerable nearby targets. Because the pairing…
Patched 2026-05-15