PoC Archive PoC Archive

tag

Access-Control

Xiongmai XM530 IP Camera ONVIF Authentication Bypass (CVE-2025-65856)
CVE-2025-65856 hardware Unverified
CVE-2025-65856hardwareCRITICAL 9.8Unverified2026-07-06Twonky Server 8.5.2 Unauthenticated `/nmc/rpc/` Auth Bypass & Admin Credential Log Leak (CVE-2025-13315) EPSS 33%
CVE-2025-13315 network Unpatched
CVE-2025-13315networkCRITICAL 9.8Unpatched2026-07-06FreePBX Framework Module Authentication Bypass via Forged Authorization Header (CVE-2025-66039)
CVE-2025-66039 network Patched
CVE-2025-66039networkCRITICAL 9.8Patched2026-07-06phpVMS Unauthenticated Legacy Importer Database Wipe (CVE-2026-42569)
CVE-2026-42569 web Patched
CVE-2026-42569webCRITICALPatched2026-07-05gRPC-Go RBAC Authorization Bypass via Missing Leading Slash in `:path` (CVE-2026-33186)
CVE-2026-33186 (GHSA-p77j-4mvh-x3m3) network Patched
CVE-2026-33186networkHIGHPatched2026-07-05Apache Tomcat Split-Collection Security Constraint Bypass (CVE-2026-43515)
CVE-2026-43515 web Patched
CVE-2026-43515webHIGHPatched2026-07-05MyBB 1.8.40 Limited Admin CP User-Manager to Full Administrator Privilege Escalation
None assigned as of 2026-07-03 (see Notes — CVE-2026-45115 identifies a separate, already-patched MyBB issue) web Unpatched
None assigned as of 2026-07-03webHIGHUnpatched2026-07-03Unauthenticated RCE in Joomla Content Editor (JCE) Profile Import (CVE-2026-48907) KEV EPSS 78%
CVE-2026-48907 web Patched
CVE-2026-48907webCRITICAL 10Patched2026-07-01SP Page Builder (Joomla) Unauthenticated File Upload RCE (CVE-2026-48908) KEV EPSS 15%
CVE-2026-48908 (GHSA-8fwr-8fxr-8v2p) web Patched
CVE-2026-48908webCRITICAL 10Patched2026-06-30