PoC Archive PoC Archive

tag

Arbitrary-File-Write

Microsoft SCCM — AdminService CAB Extraction Path-Traversal to SYSTEM RCE (CVE-2026-47301)
CVE-2026-47301 network Unverified
CVE-2026-47301networkCRITICAL 9.8Unverified2026-08-15Crawl4AI Docker API Server Arbitrary File Write via `output_path` (CVE-2026-56260)
CVE-2026-56260 (GHSA-365w-hqf6-vxfg) web Patched
CVE-2026-56260webCRITICAL 9.1Patched2026-07-12ZimaOS Arbitrary File Write via Unvalidated File API Path — CVE-2026-28286
CVE-2026-28286 web Unverified
CVE-2026-28286webCRITICALUnverified2026-07-05Veno File Manager Arbitrary PHP File Overwrite (CVE-2026-37068)
CVE-2026-37068 web Unverified
CVE-2026-37068webCRITICALUnverified2026-07-05Responsive Filemanager 9.14.0 — Unauthenticated RCE via Duplicate File (CVE-2026-39023)
CVE-2026-39023 web Unpatched
CVE-2026-39023webCRITICALUnpatched2026-07-05OpenPLC_v3 glue_generator Path Traversal — CVE-2026-31156
CVE-2026-31156 hardware Unverified
CVE-2026-31156hardwareHIGHUnverified2026-07-05Node.js `tar` Package Symlink Path Traversal — CVE-2026-29786
CVE-2026-29786 misc Patched
CVE-2026-29786miscHIGHPatched2026-07-05FUXA SCADA/HMI — Unauthenticated Path Traversal to Remote Code Execution (CVE-2026-25895) EPSS 11%
CVE-2026-25895 web Patched
CVE-2026-25895webCRITICAL 9.8Patched2026-07-05Fireshare Unauthenticated Arbitrary File Write/Overwrite — CVE-2026-54337
CVE-2026-54337 (see [GHSA-hmh2-6g84-q8jx](https://github.com/ShaneIsrael/fireshare/security/advisories/GHSA-hmh2-6g84-q8jx)) web Unverified
CVE-2026-54337webINFOUnverified2026-07-05exiftool-vendored.js Argument Injection via Newline-Delimited Tag Names (CVE-2026-43893)
CVE-2026-43893 / GHSA-cw26-7653-2rp5 misc Patched
CVE-2026-43893 / GHSA-cw26-7653-2rp5miscHIGH 8.2Patched2026-07-05Casdoor Authenticated Path Traversal to Arbitrary File Write (CVE-2026-6815)
CVE-2026-6815 web Unverified
CVE-2026-6815webHIGHUnverified2026-07-05ApostropheCMS Import — Malicious Tar Archive Path Traversal (CVE-2026-32731)
CVE-2026-32731 web Patched
CVE-2026-32731webHIGHPatched2026-07-05Apktool Resource Table Path Traversal — Malicious APK Builder (CVE-2026-39973)
CVE-2026-39973 misc Patched
CVE-2026-39973miscHIGHPatched2026-07-05Amazon WorkSpaces Skylight Workspace Config Service Local Privilege Escalation (CVE-2026-7791)
CVE-2026-7791 cloud Unverified
CVE-2026-7791cloudHIGHUnverified2026-07-05AdonisJS bodyparser Path Traversal to Arbitrary File Write (CVE-2026-21440)
CVE-2026-21440 (GHSA-gvq6-hvvp-h34h) web Patched
CVE-2026-21440webCRITICAL 9.2Patched2026-07-05WinRAR Archive Extraction Path Traversal (CVE-2025-6218) KEV EPSS 90%
CVE-2025-6218 misc Unverified
CVE-2025-6218miscHIGHUnverified2026-05-15