PoC Archive PoC Archive

tag

Cwe-287

Ivanti Endpoint Manager Mobile (EPMM) Unauthenticated Remote API Access (CVE-2023-35078) KEV RW EPSS 100%
CVE-2023-35078 (Ivanti advisory; CWE-287 per NVD) network Unverified
CVE-2023-35078networkCRITICAL 9.8Unverified2026-08-09Check Point Security Management / Multi-Domain Server SmartConsole Authentication Bypass via Forged Application Certificate Bind (CVE-2026-16232) KEV EPSS 72%
CVE-2026-16232 network Patched
CVE-2026-16232networkCRITICAL 9.1Patched2026-08-09Xiongmai XM530 IP Camera ONVIF Authentication Bypass (CVE-2025-65856)
CVE-2025-65856 hardware Unverified
CVE-2025-65856hardwareCRITICAL 9.8Unverified2026-07-06WP Directory Kit Auto-Login Authentication Bypass to Full Site Takeover (CVE-2025-13390)
CVE-2025-13390 web Patched
CVE-2025-13390webCRITICAL 10Patched2026-07-06RestroPress WordPress Plugin Unauthenticated Information Exposure Leading to JWT Forgery / Account Takeover (CVE-2025-9209)
CVE-2025-9209 web Unpatched
CVE-2025-9209webCRITICAL 9.8Unpatched2026-07-06PrestaShop Checkout Zero-Click Account Takeover via ExpressCheckout Endpoint (CVE-2025-61922)
CVE-2025-61922 web Patched
CVE-2025-61922webCRITICAL 9.1Patched2026-07-06Oracle Identity Manager `;.wadl` Authentication Bypass + Groovy Script RCE (CVE-2025-61757) KEV EPSS 88%
CVE-2025-61757 web Unpatched
CVE-2025-61757webCRITICAL 9.8Unpatched2026-07-06JAY Login & Register "Switch Back" Cookie Authentication Bypass (CVE-2025-14440)
CVE-2025-14440 web Unverified
CVE-2025-14440webCRITICAL 9.8Unverified2026-07-06Grafana Enterprise SCIM User ID Collision / Impersonation (CVE-2025-41115) EPSS 19%
CVE-2025-41115 web Patched
CVE-2025-41115webCRITICAL 10Patched2026-07-06FreePBX Framework Module Authentication Bypass via Forged Authorization Header (CVE-2025-66039)
CVE-2025-66039 network Patched
CVE-2025-66039networkCRITICAL 9.8Patched2026-07-06CrushFTP AS2 Header Authentication Bypass (CVE-2025-54309) KEV EPSS 95%
CVE-2025-54309 web Patched
CVE-2025-54309webCRITICAL 9Patched2026-07-06Rack::Session::Cookie Decrypt-Failure Fallback to Unencrypted Cookies (CVE-2026-39324)
CVE-2026-39324 / GHSA-33qg-7wpp-89cq web Patched
CVE-2026-39324 / GHSA-33qg-7wpp-89cqwebCRITICALPatched2026-07-05PocketBase OAuth2 Account Pre-Hijacking (CVE-2026-44166)
CVE-2026-44166 / [GHSA-pq7p-mc74-g65w](https://github.com/pocketbase/pocketbase/security/advisories/GHSA-pq7p-mc74-g65w) web Patched
CVE-2026-44166 / [GHSA-pq7p-mc74-g65w]webMEDIUM 6.1Patched2026-07-05LiteLLM Authentication Bypass via OIDC Userinfo Cache Key Collision (CVE-2026-35030)
CVE-2026-35030 web Patched
CVE-2026-35030webCRITICAL 9.1Patched2026-07-05HPE Aruba AOS-CX Pre-Auth REST API Bypass via nginx Version Smuggling (CVE-2026-23813)
CVE-2026-23813 network Patched
CVE-2026-23813networkCRITICAL 9.8Patched2026-07-05Burst Statistics WordPress Plugin Authentication Bypass to Admin Account Takeover (CVE-2026-8181) EPSS 15%
CVE-2026-8181 web Patched
CVE-2026-8181webCRITICAL 9.8Patched2026-07-05