PoC Archive PoC Archive

tag

Cwe-288

WordPress Simple Link Directory Unauthenticated Password Reset to Admin Takeover (CVE-2025-49901)
CVE-2025-49901 web Patched
CVE-2025-49901webCRITICAL 9.8Patched2026-07-06WordPress Mobile Builder Plugin JWT Authentication Bypass to Admin Account Creation (CVE-2025-68860)
CVE-2025-68860 web Unpatched
CVE-2025-68860webCRITICAL 9.8Unpatched2026-07-06FortiWeb `cgi-bin/fwbcgi` Path Traversal Authentication Bypass Leading to Rogue Admin Creation (CVE-2025-64446) KEV EPSS 92%
CVE-2025-64446 network Unverified
CVE-2025-64446networkCRITICAL 9.8Unverified2026-07-06NVIDIA Triton Inference Server SageMaker Auth Bypass to Unauthenticated RCE (CVE-2026-24207)
CVE-2026-24207 (sibling: CVE-2026-24206, Vertex AI, analysis only) network Patched
CVE-2026-24207networkCRITICAL 9.8Patched2026-07-05Fortinet FortiOS / FortiProxy Authentication Bypass (CVE-2024-55591) KEV RW EPSS 98%
CVE-2024-55591 (Fortinet FG-IR-24-535) web Unverified
CVE-2024-55591webCRITICAL 9.6Unverified2026-05-16