PoC Archive PoC Archive

tag

Cisa-Kev

Oracle E-Business Suite Pre-Authentication RCE Chain (CVE-2025-61882) KEV RW EPSS 100%
CVE-2025-61882 (Oracle Security Alert, out-of-band, October 2025) web Patched
CVE-2025-61882webCRITICAL 9.8Patched2026-08-09Ivanti Endpoint Manager Mobile (EPMM) Unauthenticated Remote API Access (CVE-2023-35078) KEV RW EPSS 100%
CVE-2023-35078 (Ivanti advisory; CWE-287 per NVD) network Unverified
CVE-2023-35078networkCRITICAL 9.8Unverified2026-08-09Ivanti Connect Secure / Policy Secure / ZTA Gateways Remote Unauthenticated Stack-Based Buffer Overflow (CVE-2025-22457) KEV RW EPSS 100%
CVE-2025-22457 network Unpatched
CVE-2025-22457networkCRITICAL 9Unpatched2026-08-09Check Point Security Management / Multi-Domain Server SmartConsole Authentication Bypass via Forged Application Certificate Bind (CVE-2026-16232) KEV EPSS 72%
CVE-2026-16232 network Patched
CVE-2026-16232networkCRITICAL 9.1Patched2026-08-09SimpleHelp OIDC Authentication Bypass (CVE-2026-48558) KEV EPSS 12%
CVE-2026-48558 web Patched
CVE-2026-48558webCRITICAL 9.8Patched2026-07-05Langflow Missing-Authentication Remote Code Execution (CVE-2025-3248) KEV RW EPSS 100%
CVE-2025-3248 web Patched
CVE-2025-3248webCRITICAL 9.8Patched2026-07-03Fortinet FortiClient EMS Pre-Auth Bypass — "FortiBleed" (CVE-2026-35616) KEV EPSS 91%
CVE-2026-35616 network Patched
CVE-2026-35616networkCRITICAL 9.1Patched2026-07-03Unauthenticated RCE in Mirasvit Full Page Cache Warmer for Magento 2 (CVE-2026-45247) KEV EPSS 28%
CVE-2026-45247 web Unverified
CVE-2026-45247webCRITICAL 9.3Unverified2026-07-01Unauthenticated RCE in Joomla Content Editor (JCE) Profile Import (CVE-2026-48907) KEV EPSS 78%
CVE-2026-48907 web Patched
CVE-2026-48907webCRITICAL 10Patched2026-07-01Cisco Unified CM WebDialer SSRF to Arbitrary File Write / RCE (CVE-2026-20230) KEV EPSS 88%
CVE-2026-20230 network Unverified
CVE-2026-20230networkCRITICAL 8.6Unverified2026-07-01GNU Inetutils telnetd Unauthenticated Root RCE via NEW-ENVIRON (CVE-2026-24061) KEV EPSS 98%
CVE-2026-24061 network Patched
CVE-2026-24061networkCRITICAL 9.8Patched2026-06-30Ubiquiti UniFi OS Unauthenticated RCE Chain (CVE-2026-34908 / CVE-2026-34909 / CVE-2026-34910) KEV EPSS 85%
CVE-2026-34908, CVE-2026-34909, CVE-2026-34910 network Patched
CVE-2026-34908, CVE-2026-34909, CVE-2026-34910networkCRITICAL 10Patched2026-06-28Splunk Enterprise Pre-Auth RCE via PostgreSQL Sidecar (CVE-2026-20253) KEV EPSS 97%
CVE-2026-20253 web Patched
CVE-2026-20253webCRITICALPatched2026-06-28Ivanti Sentry Pre-Auth RCE + Auth Bypass (CVE-2026-10520 / CVE-2026-10523) KEV EPSS 100%
CVE-2026-10520, CVE-2026-10523 network Patched
CVE-2026-10520, CVE-2026-10523networkCRITICAL 10Patched2026-06-28Cisco Catalyst SD-WAN Manager Privilege Escalation (CVE-2026-20245) KEV EPSS 25%
CVE-2026-20245 network Unpatched
CVE-2026-20245networkHIGH 7.8Unpatched2026-06-28Check Point Remote Access VPN IKEv1 Auth Bypass (CVE-2026-50751) KEV RW EPSS 84%
CVE-2026-50751 network Patched
CVE-2026-50751networkCRITICAL 9.3Patched2026-06-28Linux nf_tables Use-After-Free Local Privilege Escalation (CVE-2024-1086) KEV RW EPSS 28%
CVE-2024-1086 binary Patched
CVE-2024-1086binaryHIGH 7.8Patched2026-05-17