PoC Archive PoC Archive

tag

CWE-502

TeamCity — Unauthenticated RCE via Agent Polling Deserialization (CVE-2026-63077) KEV EPSS 88%
CVE-2026-63077 web Patched
CVE-2026-63077webCRITICAL 9.8Patched2026-08-09Sitecore XP Report.ashx Insecure Deserialization RCE (CVE-2021-42237) KEV RW EPSS 98%
CVE-2021-42237 (Sitecore advisory SC2021-003-499266) web Patched
CVE-2021-42237webCRITICAL 9.8Patched2026-07-11SAP NetWeaver Visual Composer Unrestricted File Upload RCE (CVE-2025-31324) KEV RW EPSS 100%
CVE-2025-31324 web Patched
CVE-2025-31324webCRITICAL 10Patched2026-07-06Roundcube Webmail Post-Auth RCE via PHP Object Deserialization (CVE-2025-49113) KEV EPSS 99%
CVE-2025-49113 web Patched
CVE-2025-49113webCRITICAL 9.9Patched2026-07-06Laravel Livewire Remote Code Execution via Known APP_KEY (CVE-2025-54068) KEV EPSS 96%
CVE-2025-54068 web Patched
CVE-2025-54068webCRITICAL 9.8Patched2026-07-06GiveWP Unauthenticated PHP Object Injection via Weak Serialized-Data Regex Check (CVE-2025-22777)
CVE-2025-22777 web Patched
CVE-2025-22777webCRITICAL 9.8Patched2026-07-06Apache Parquet-Avro Schema Deserialization RCE/SSRF — Incomplete-Fix Bypass (CVE-2025-30065) EPSS 43%
CVE-2025-30065 misc Patched
CVE-2025-30065miscCRITICAL 9.8Patched2026-07-06Apache Camel `camel-consul` ConsulRegistry Deserialization RCE (CVE-2026-27172)
CVE-2026-27172 web Patched
CVE-2026-27172webCRITICAL 9.8Patched2026-07-06WP Activity Log Unauthenticated PHP Object Injection — CVE-2026-54806
CVE-2026-54806 web Patched
CVE-2026-54806webCRITICAL 9.8Patched2026-07-05SP LMS PHP Object Injection → Unauthenticated RCE (CVE-2026-48909)
CVE-2026-48909 (GHSA-gf8c-xmwj-whrh) web Patched
CVE-2026-48909webCRITICAL 9.5Patched2026-07-05MLflow / MLServer Insecure Pickle Deserialization RCE — CVE-2026-0596
CVE-2026-0596 (GHSA-rvhj-8chj-8v3c) web Unverified
CVE-2026-0596webCRITICAL 9.6Unverified2026-07-05Jenkins ClassFilter Deserialization Bypass → Arbitrary File Read — CVE-2026-53435 EPSS 53%
CVE-2026-53435 (Jenkins SECURITY-3707) web Patched
CVE-2026-53435webHIGH 9.1Patched2026-07-05Integration for ActiveCampaign Unauthenticated PHP Object Injection via Unsafe Deserialization (CVE-2026-9691)
CVE-2026-9691 web Unpatched
CVE-2026-9691webHIGH 8.1Unpatched2026-07-05Everest Forms Unauthenticated PHP Object Injection to RCE (CVE-2026-3296)
CVE-2026-3296 web Patched
CVE-2026-3296webCRITICAL 9.8Patched2026-07-05docling-core Unsafe YAML Deserialization Leading to Code Execution — CVE-2026-24009
CVE-2026-24009 misc Patched
CVE-2026-24009miscHIGHPatched2026-07-05Apache MINA acceptMatchers Deserialization Filter Bypass to RCE (CVE-2026-42779)
CVE-2026-42779 network Patched
CVE-2026-42779networkCRITICAL 9.8Patched2026-07-05