PoC Archive PoC Archive

tag

Cloud

  • CVE-2025-55182 web CRITICAL 10 KEV Ransomware EPSS 100%

    React2Shell - Next.js RSC Unauthenticated RCE

    CVE-2025-55182 is a CVSS 10.0 unauthenticated Remote Code Execution vulnerability in Next.js applications using React Server Components (RSC) with the App Router. The exploit abuses unsafe deserialization of the RSC wire format: a crafted multipart POST…

    Patched 2026-05-17
  • CVE-2025-54914 cloud CRITICAL 10

    Azure Networking Privilege Escalation via Missing Privilege Check

    CVE-2025-54914 is a critical privilege escalation vulnerability (CVSS 10.0) in Microsoft Azure Networking. Discovered by Mark Mallia and disclosed on September 4, 2025, the flaw arises from a missing authorization check in the GetRouteTable API code path. A…

    Patched 2026-05-17