PoC Archive PoC Archive

tag

Command-Injection

UniFi OS -- Unauthenticated Command Injection RCE (CVE-2026-34910) KEV EPSS 87%
CVE-2026-34910, CVE-2026-34909, CVE-2026-34908 network Patched
CVE-2026-34910, CVE-2026-34909, CVE-2026-34908networkCRITICAL 10Patched2026-08-16CyberPanel Pre-Auth Remote Code Execution via getresetstatus Command Injection (CVE-2024-51378) KEV RW EPSS 95%
CVE-2024-51378 web Patched
CVE-2024-51378webCRITICAL 10Patched2026-08-09D-Link DIR-820L `get_set.ccp` LAN Configuration OS Command Injection (CVE-2022-26258) KEV EPSS 80%
CVE-2022-26258 network Unverified
CVE-2022-26258networkCRITICAL 9.8Unverified2026-07-11tj-actions/branch-names GitHub Actions Command Injection (CVE-2025-54416)
CVE-2025-54416 cloud Patched
CVE-2025-54416cloudCRITICAL 9.1Patched2026-07-06React Native Community CLI Metro Dev Server `/open-url` OS Command Injection (CVE-2025-11953) KEV EPSS 94%
CVE-2025-11953 network Patched
CVE-2025-11953networkCRITICAL 9.8Patched2026-07-06pgAdmin 4 Restore Feature Regex-Bypass Command Injection RCE (CVE-2025-13780)
CVE-2025-13780 web Unverified
CVE-2025-13780webCRITICAL 9.1Unverified2026-07-06Mongoose `populate()` Match `$where` Bypass Command Injection (CVE-2025-23061)
CVE-2025-23061 web Patched
CVE-2025-23061webCRITICAL 9Patched2026-07-06HPE OneView `id-pools/executeCommand` OS Command Injection (CVE-2025-37164) KEV EPSS 90%
CVE-2025-37164 network Unpatched
CVE-2025-37164networkCRITICAL 10Unpatched2026-07-06Hoverfly Middleware Command Injection to RCE (CVE-2025-54123) EPSS 11%
CVE-2025-54123 web Patched
CVE-2025-54123webCRITICAL 9.8Patched2026-07-06D-Link AX1500 SetDeviceSettings `DeviceName` OS Command Injection (CVE-2025-60854)
CVE-2025-60854 network Patched
CVE-2025-60854networkCRITICAL 9.8Patched2026-07-06Zyxel VMG3625-T50B Authenticated Command Injection to Root SSH Access (CVE-2026-1459)
CVE-2026-1459 network Unverified
CVE-2026-1459networkHIGHUnverified2026-07-05Weblate Arbitrary File Read via ssh-keyscan Host Argument Injection — CVE-2026-24126
CVE-2026-24126 web Patched
CVE-2026-24126webHIGH 6.5Patched2026-07-05Vim Modeline `path` Option Backtick-Expansion Command Injection (CVE-2026-44656)
CVE-2026-44656 binary Patched
CVE-2026-44656binaryHIGHPatched2026-07-05TP-Link Tapo C260 Unauthenticated-to-Root RCE Chain — CVE-2026-0651
CVE-2026-0651 (chained with CVE-2026-0652, CVE-2026-0653) network Unverified
CVE-2026-0651networkCRITICALUnverified2026-07-05TP-Link DHCP Option 66 Unauthenticated RCE — CVE-2026-11834
CVE-2026-11834 network Unverified
CVE-2026-11834networkCRITICALUnverified2026-07-05Supply Chain Command Injection in AWS CDK's NodejsFunction — CVE-2026-11417
CVE-2026-11417 cloud Patched
CVE-2026-11417cloudHIGH 3.1Patched2026-07-05Spinnaker Clouddriver — Git Clone Shell Injection RCE (CVE-2026-32604)
CVE-2026-32604 (CWE-78) cloud Patched
CVE-2026-32604cloudCRITICAL 10Patched2026-07-05Sherlock CI `pull_request_target` Command Injection → GitHub Actions Secret Exfiltration (CVE-2026-44590)
CVE-2026-44590 cloud Patched
CVE-2026-44590cloudCRITICAL 9.3Patched2026-07-05Samba spoolss Print Job Command Injection RCE (CVE-2026-4480) EPSS 14%
CVE-2026-4480 network Patched
CVE-2026-4480networkCRITICALPatched2026-07-05Red Hat Cockpit `logsJournal.jsx` Shell Injection RCE (CVE-2026-4802)
CVE-2026-4802 web Unpatched
CVE-2026-4802webHIGHUnpatched2026-07-05rclone RC API Unauthenticated Remote Code Execution (CVE-2026-41179)
CVE-2026-41179 web Patched
CVE-2026-41179webCRITICAL 9.8Patched2026-07-05OS Command Injection in KubeAI via Model URL (CVE-2026-34940)
CVE-2026-34940 cloud Patched
CVE-2026-34940cloudHIGH 8.7Patched2026-07-05OpenXDMoD `user_interface.php` Report Title Command Injection (CVE-2026-45777)
CVE-2026-45777 web Patched
CVE-2026-45777webCRITICALPatched2026-07-05OpenClaw Gateway WebSocket Authentication Bypass RCE — CVE-2026-28466
CVE-2026-28466 network Patched
CVE-2026-28466networkCRITICALPatched2026-07-05OliveTin OS Command Injection via Shell Mode Arguments (CVE-2026-27626)
CVE-2026-27626 / GHSA-49gm-hh7w-wfvf web Unverified
CVE-2026-27626 / GHSA-49gm-hh7w-wfvfwebCRITICAL 9.9Unverified2026-07-05MR9600 Router Bluetooth/JNAP Management Interface RCE Injection (CVE-2026-6992)
CVE-2026-6992 network Unverified
CVE-2026-6992networkHIGHUnverified2026-07-05MeiG Smart FORGE_SLT711 GoAhead Unauthenticated OS Command Injection (CVE-2026-36356) EPSS 14%
CVE-2026-36356 network Unverified
CVE-2026-36356networkCRITICALUnverified2026-07-05MCPJam Inspector Unauthenticated Command Injection RCE (CVE-2026-23744) EPSS 45%
CVE-2026-23744 web Patched
CVE-2026-23744webCRITICALPatched2026-07-05MCPJam Inspector / Arcane MCP Connect Command Injection RCE via Host-Header Vhost Routing (CVE-2026-23520)
CVE-2026-23520 web Patched
CVE-2026-23520webCRITICALPatched2026-07-05Ivanti EPMM Pre-Auth RCE via Bash Arithmetic Expansion (CVE-2026-1281 / CVE-2026-1340) KEV EPSS 82%
CVE-2026-1281, CVE-2026-1340 network Patched
CVE-2026-1281, CVE-2026-1340networkCRITICALPatched2026-07-05HAXcms Git.php OS Command Injection (CVE-2026-46394)
CVE-2026-46394 web Patched
CVE-2026-46394webHIGH 7.2Patched2026-07-05Group-Office TNEF Attachment Handler OS Command Injection (CVE-2026-25512) EPSS 19%
CVE-2026-25512 web Patched
CVE-2026-25512webCRITICAL 9.4Patched2026-07-05Gotenberg 8.29.1 Unauthenticated ExifTool Metadata Key Injection RCE (CVE-2026-42589)
CVE-2026-42589 web Patched
CVE-2026-42589webCRITICAL 9.8Patched2026-07-05Fortinet FortiSandbox "Start VNC" OS Command Injection (CVE-2026-25089) KEV EPSS 76%
CVE-2026-25089 network Patched
CVE-2026-25089networkCRITICAL 9.8Patched2026-07-05ExifTool Metadata Field Command Injection (macOS) — CVE-2026-3102
CVE-2026-3102 binary Patched
CVE-2026-3102binaryHIGHPatched2026-07-05Coolify Authenticated Remote Command Injection via Deployment Config (CVE-2026-34038)
CVE-2026-34038 (GHSA-qqrq-r9h4-x6wp) web Patched
CVE-2026-34038webCRITICAL 10Patched2026-07-05Cockpit Unauthenticated Remote Code Execution via SSH Argument Injection (CVE-2026-4631) EPSS 15%
CVE-2026-4631 (GHSA-m4gv-x78h-3427) web Patched
CVE-2026-4631webCRITICAL 9.8Patched2026-07-05Centreon Multi-Vector RCE — Path Traversal, Command Injection & Blind SQLi (CVE-2026-2749)
CVE-2026-2749 (bundled with related CVE-2026-2750, CVE-2026-2751) web Patched
CVE-2026-2749webCRITICALPatched2026-07-05Cacti Authenticated OS Command Injection via Host Notes Variable (CVE-2026-39949)
CVE-2026-39949 web Patched
CVE-2026-39949webHIGHPatched2026-07-05curl SMTP EXPN Recipient CRLF Command Injection
None assigned as of 2026-07-03 network Unverified
None assigned as of 2026-07-03networkMEDIUMUnverified2026-07-03Authenticated Command Injection in LiteLLM MCP Test Endpoints (CVE-2026-42271) KEV EPSS 84%
CVE-2026-42271 web Patched
CVE-2026-42271webHIGH 8.7Patched2026-07-01Ubiquiti UniFi OS Unauthenticated RCE Chain (CVE-2026-34908 / CVE-2026-34909 / CVE-2026-34910) KEV EPSS 85%
CVE-2026-34908, CVE-2026-34909, CVE-2026-34910 network Patched
CVE-2026-34908, CVE-2026-34909, CVE-2026-34910networkCRITICAL 10Patched2026-06-28Cisco Catalyst SD-WAN Manager Privilege Escalation (CVE-2026-20245) KEV EPSS 25%
CVE-2026-20245 network Unpatched
CVE-2026-20245networkHIGH 7.8Unpatched2026-06-28Notepad++ <= 8.9.6 Multiple Vulnerabilities (CVE-2026-48770, CVE-2026-48778, CVE-2026-48800)
CVE-2026-48770, CVE-2026-48778, CVE-2026-48800 binary Patched
CVE-2026-48770, CVE-2026-48778, CVE-2026-48800binaryHIGH 5Patched2026-05-28Palo Alto PAN-OS GlobalProtect Unauthenticated RCE (CVE-2024-3400) KEV RW EPSS 100%
CVE-2024-3400 web Patched
CVE-2024-3400webCRITICAL 10Patched2026-05-17