PoC Archive PoC Archive

tag

Cwe-22

Microweber CMS Unauthenticated Path Traversal → Arbitrary File Read (CVE-2026-65694)
CVE-2026-65694 (VulnCheck advisory) web Patched
CVE-2026-65694webHIGH 7.5Patched2026-07-31Rails Active Storage Arbitrary File Read to RCE via libvips Unfuzzed Loaders (CVE-2026-66066) EPSS 28%
CVE-2026-66066 (GHSA-xr9x-r78c-5hrm) web Patched
CVE-2026-66066webCRITICAL 9.5Patched2026-07-27Adobe ColdFusion RDS Path Traversal → Arbitrary File Read/Write → RCE (CVE-2026-48282) KEV EPSS 42%
CVE-2026-48282 (Adobe APSB26-68) web Patched
CVE-2026-48282webCRITICAL 10Patched2026-07-19Crawl4AI Docker API Server Arbitrary File Write via `output_path` (CVE-2026-56260)
CVE-2026-56260 (GHSA-365w-hqf6-vxfg) web Patched
CVE-2026-56260webCRITICAL 9.1Patched2026-07-12ZKTeco BioTime v8.5.5 Unauthenticated Path Traversal / Arbitrary File Read via iclock API (CVE-2023-38950) KEV EPSS 85%
CVE-2023-38950 web Patched
CVE-2023-38950webHIGH 7.5Patched2026-07-11ThinkPHP 5.0.24 File Inclusion Leading to Remote Code Execution (CVE-2025-63888)
CVE-2025-63888 web Unverified
CVE-2025-63888webCRITICAL 9.8Unverified2026-07-06Samsung MagicINFO 9 Server Unauthenticated Path Traversal to RCE (CVE-2025-4632) KEV EPSS 24%
CVE-2025-4632 web Patched
CVE-2025-4632webCRITICAL 9.8Patched2026-07-06Python tarfile `filter="data"` Bypass via PATH_MAX/realpath Confusion (CVE-2025-4517)
CVE-2025-4517 misc Patched
CVE-2025-4517miscCRITICAL 9.4Patched2026-07-06Pterodactyl Panel Unauthenticated Path Traversal via locale.json Leaking Database Credentials (CVE-2025-49132) EPSS 53%
CVE-2025-49132 web Patched
CVE-2025-49132webCRITICAL 10Patched2026-07-06Mitel MiCollab Path Normalization Bypass to Internal Endpoints (CVE-2025-52913)
CVE-2025-52913 network Unverified
CVE-2025-52913networkCRITICAL 9.8Unverified2026-07-06FortiWeb `cgi-bin/fwbcgi` Path Traversal Authentication Bypass Leading to Rogue Admin Creation (CVE-2025-64446) KEV EPSS 92%
CVE-2025-64446 network Unverified
CVE-2025-64446networkCRITICAL 9.8Unverified2026-07-06Veno File Manager Path Traversal to Arbitrary File Read (CVE-2026-37066)
CVE-2026-37066 web Unverified
CVE-2026-37066webHIGHUnverified2026-07-05Veno File Manager Arbitrary File Deletion (CVE-2026-37065)
CVE-2026-37065 web Unverified
CVE-2026-37065webHIGHUnverified2026-07-05UnPoller Path Traversal / Arbitrary File Read via file:// Password Prefix (CVE-2026-36851)
CVE-2026-36851 misc Unverified
CVE-2026-36851miscHIGH 7.5Unverified2026-07-05Tandoor Recipes Authenticated Local File Disclosure via Recipe Import (CVE-2026-25964)
CVE-2026-25964 (GHSA-6485-jr28-52xx) web Patched
CVE-2026-25964webMEDIUM 4.9Patched2026-07-05OpenEMR EtherFax Module Authenticated Arbitrary File Read (CVE-2026-24849)
CVE-2026-24849 web Patched
CVE-2026-24849webCRITICAL 6.5Patched2026-07-05Nezha Dashboard Path Traversal → JWT Secret Leak → Token Forgery — CVE-2026-53519
CVE-2026-53519 (GHSA-5c25-7vpj-9mqh) web Patched
CVE-2026-53519webINFOPatched2026-07-05mcp-atlassian Path Traversal via confluence_upload_attachment (CVE-2026-27825) EPSS 13%
CVE-2026-27825 (read-side twin of GHSA-xjgw-4wvw-rgm4) web Patched
CVE-2026-27825webCRITICAL 9.3Patched2026-07-05Langflow Knowledge Base Path Traversal / Arbitrary Directory Deletion (CVE-2026-42048)
CVE-2026-42048 (GHSA-9whx-c884-c68q) web Patched
CVE-2026-42048webHIGHPatched2026-07-05Gravity Forms Path Traversal → Arbitrary File Deletion (CVE-2026-48866)
CVE-2026-48866 web Patched
CVE-2026-48866webCRITICAL 9.6Patched2026-07-05FUXA SCADA/HMI — Unauthenticated Path Traversal to Remote Code Execution (CVE-2026-25895) EPSS 11%
CVE-2026-25895 web Patched
CVE-2026-25895webCRITICAL 9.8Patched2026-07-05Casdoor Authenticated Path Traversal to Arbitrary File Write (CVE-2026-6815)
CVE-2026-6815 web Unverified
CVE-2026-6815webHIGHUnverified2026-07-05AdonisJS bodyparser Path Traversal to Arbitrary File Write (CVE-2026-21440)
CVE-2026-21440 (GHSA-gvq6-hvvp-h34h) web Patched
CVE-2026-21440webCRITICAL 9.2Patched2026-07-05Cisco Catalyst SD-WAN Manager Arbitrary File Write (CVE-2026-20262) KEV EPSS 28%
CVE-2026-20262 network Unverified
CVE-2026-20262networkMEDIUM 6.5Unverified2026-07-01