PoC Archive PoC Archive

tag

Cisa-Kev

  • CVE-2025-61882 web CRITICAL 9.8 KEV Ransomware EPSS 100%

    Oracle E-Business Suite Pre-Authentication RCE Chain (CVE-2025-61882)

    CVE-2025-61882 is an unauthenticated remote code execution chain in Oracle E-Business Suite 12.2.3 through 12.2.14. An attacker POSTs an XML document to the unauthenticated /OAHTML/configurator/UiServlet endpoint; the servlet extracts a returnurl element from…

    Patched 2026-08-09
  • CVE-2023-35078 network CRITICAL 9.8 KEV Ransomware EPSS 100%

    Ivanti Endpoint Manager Mobile (EPMM) Unauthenticated Remote API Access (CVE-2023-35078)

    Ivanti Endpoint Manager Mobile (EPMM, formerly MobileIron Core) fails to enforce authentication on specific paths beneath its /mifs/aad/api/ administrative API. An unauthenticated remote attacker can issue a plain GET…

    Unverified 2026-08-09
  • CVE-2025-22457 network CRITICAL 9 KEV Ransomware EPSS 100%

    Ivanti Connect Secure / Policy Secure / ZTA Gateways Remote Unauthenticated Stack-Based Buffer Overflow (CVE-2025-22457)

    CVE-2025-22457 is a remote, pre-authentication stack-based buffer overflow (CWE-121) in the HTTPS request-handling path of Ivanti Connect Secure and sibling appliances. A single oversized X-Forwarded-For request header overflows a fixed-size stack buffer in…

    Unpatched 2026-08-09
  • CVE-2026-16232 network CRITICAL 9.1 KEV EPSS 71%

    Check Point Security Management / Multi-Domain Server SmartConsole Authentication Bypass via Forged Application Certificate Bind (CVE-2026-16232)

    CVE-2026-16232 is an unauthenticated authentication bypass (CWE-287) in the Check Point SmartConsole login path on Security Management and Multi-Domain Management servers. During the legacy SIC/CPMI bootstrap the management server volunteers its own SIC…

    Patched 2026-08-09
  • CVE-2026-48558 web CRITICAL 9.8 KEV EPSS 11%

    SimpleHelp OIDC Authentication Bypass (CVE-2026-48558)

    When OIDC authentication is enabled, SimpleHelp accepts identity tokens (ID Tokens/JWTs) at its OIDC callback endpoint without verifying their cryptographic signature — including tokens using alg: none. A remote, unauthenticated attacker can forge a JWT with…

    Patched 2026-07-05
  • CVE-2025-3248 web CRITICAL 9.8 KEV Ransomware EPSS 100%

    Langflow Missing-Authentication Remote Code Execution (CVE-2025-3248)

    CVE-2025-3248 is a missing-authentication vulnerability in Langflow's code-validation API. The /api/v1/validate/code endpoint accepts and executes arbitrary Python code submitted by any client, with no authentication check on the route, allowing an…

    Patched 2026-07-03
  • CVE-2026-35616 network CRITICAL 9.1 KEV EPSS 89%

    Fortinet FortiClient EMS Pre-Auth Bypass — "FortiBleed" (CVE-2026-35616)

    CVE-2026-35616 is a pre-authentication bypass in Fortinet FortiClient EMS's certificate-chain authentication handler (certchainauth.py), which trusts the X-SSL-CLIENT-VERIFY header directly without performing real cryptographic validation of the presented…

    Patched 2026-07-03
  • CVE-2026-45247 web CRITICAL 9.3 KEV EPSS 28%

    Unauthenticated RCE in Mirasvit Full Page Cache Warmer for Magento 2 (CVE-2026-45247)

    CVE-2026-45247 is a PHP object injection / insecure deserialization vulnerability in Mirasvit's Full Page Cache Warmer extension for Magento 2. The extension processes attacker-controlled data from the CacheWarmer cookie and passes it directly to PHP's native…

    Unverified 2026-07-01
  • CVE-2026-48907 web CRITICAL 10 KEV EPSS 56%

    Unauthenticated RCE in Joomla Content Editor (JCE) Profile Import (CVE-2026-48907)

    CVE-2026-48907 is a critical improper access control vulnerability in the JCE extension for Joomla. The profile import workflow (index.php?option=comjce&task=profiles.import) is missing sufficient authorization checks, letting unauthenticated users create new…

    Patched 2026-07-01
  • CVE-2026-20230 network CRITICAL 8.6 KEV EPSS 83%

    Cisco Unified CM WebDialer SSRF to Arbitrary File Write / RCE (CVE-2026-20230)

    CVE-2026-20230 is a critical server-side request forgery vulnerability in Cisco Unified CM / Unified CM SME caused by improper input validation of HTTP requests processed by the WebDialer component. A remote unauthenticated attacker can chain unauthenticated…

    Unverified 2026-07-01
  • CVE-2026-24061 network CRITICAL 9.8 KEV EPSS 98%

    GNU Inetutils telnetd Unauthenticated Root RCE via NEW-ENVIRON (CVE-2026-24061)

    CVE-2026-24061 is a critical authentication bypass in GNU Inetutils telnetd that grants an unauthenticated network attacker an immediate root shell. The NEW-ENVIRON Telnet option handler passes the USER environment variable unsanitised to /bin/login. Setting…

    Patched 2026-06-30
  • CVE-2026-34908, CVE-2026-34909, CVE-2026-34910 network CRITICAL 10 KEV EPSS 62%

    Ubiquiti UniFi OS Unauthenticated RCE Chain (CVE-2026-34908 / CVE-2026-34909 / CVE-2026-34910)

    A three-CVE unauthenticated RCE chain in Ubiquiti UniFi OS Server ≤ 5.0.6 allows a remote attacker to achieve root-level command execution with no credentials. CVE-2026-34908 and CVE-2026-34909 (improper access control + path traversal) are chained to bypass…

    Patched 2026-06-28
  • CVE-2026-20253 web CRITICAL KEV EPSS 97%

    Splunk Enterprise Pre-Auth RCE via PostgreSQL Sidecar (CVE-2026-20253)

    CVE-2026-20253 is a critical unauthenticated RCE vulnerability in Splunk Enterprise arising from a missing authentication check on the PostgreSQL sidecar service endpoint /v1/postgres/recovery/backup. An unauthenticated attacker can reach this endpoint and…

    Patched 2026-06-28
  • CVE-2026-10520, CVE-2026-10523 network CRITICAL 10 KEV EPSS 100%

    Ivanti Sentry Pre-Auth RCE + Auth Bypass (CVE-2026-10520 / CVE-2026-10523)

    Two critical vulnerabilities in Ivanti Sentry enable unauthenticated root-level RCE and arbitrary admin account creation. CVE-2026-10520 is an OS command injection in the MICS API at /mics/api/v2/sentry/mics-config/handleMessage (CVSS 10.0). CVE-2026-10523 is…

    Patched 2026-06-28
  • CVE-2026-20245 network HIGH 7.8 KEV EPSS 25%

    Cisco Catalyst SD-WAN Manager Privilege Escalation (CVE-2026-20245)

    CVE-2026-20245 is the seventh Cisco SD-WAN zero-day exploited in 2026. An authenticated attacker with netadmin privileges on Cisco Catalyst SD-WAN Manager can upload a specially crafted file to the CLI subsystem, triggering insufficient input validation and…

    Unpatched 2026-06-28
  • CVE-2026-50751 network CRITICAL 9.3 KEV Ransomware EPSS 83%

    Check Point Remote Access VPN IKEv1 Auth Bypass (CVE-2026-50751)

    CVE-2026-50751 is a critical authentication bypass in Check Point Remote Access VPN affecting gateways configured for the legacy IKEv1 protocol. A remote unauthenticated attacker can complete the deprecated IKEv1 phase-1 exchange and be authenticated as a…

    Patched 2026-06-28
  • CVE-2024-1086 binary HIGH 7.8 KEV Ransomware EPSS 28%

    Linux nf_tables Use-After-Free Local Privilege Escalation (CVE-2024-1086)

    CVE-2024-1086 is a use-after-free vulnerability in the Linux kernel's netfilter nftables subsystem that allows an unprivileged local user to escalate privileges to root. The exploit achieves a 99.4% success rate on KernelCTF images and works universally…

    Patched 2026-05-17