PoC Archive PoC Archive

tag

Cwe-78

Nagios XI 5.5.6–5.7.5 Authenticated OS Command Injection — Windows WMI Config Wizard (CVE-2021-25296) KEV EPSS 72%
CVE-2021-25296 web Patched
CVE-2021-25296webHIGH 8.8Patched2026-07-11Nagios XI 5.5.6–5.7.5 Authenticated OS Command Injection — Switch Config Wizard (CVE-2021-25297) KEV EPSS 57%
CVE-2021-25297 web Patched
CVE-2021-25297webHIGH 8.8Patched2026-07-11Nagios XI 5.5.6–5.7.5 Authenticated OS Command Injection — Cloud-VM Config Wizard (CVE-2021-25298) KEV EPSS 75%
CVE-2021-25298 web Patched
CVE-2021-25298webHIGH 8.8Patched2026-07-11D-Link DIR-820L `get_set.ccp` LAN Configuration OS Command Injection (CVE-2022-26258) KEV EPSS 80%
CVE-2022-26258 network Unverified
CVE-2022-26258networkCRITICAL 9.8Unverified2026-07-11React Native Community CLI Metro Dev Server `/open-url` OS Command Injection (CVE-2025-11953) KEV EPSS 94%
CVE-2025-11953 network Patched
CVE-2025-11953networkCRITICAL 9.8Patched2026-07-06HPE OneView `id-pools/executeCommand` OS Command Injection (CVE-2025-37164) KEV EPSS 90%
CVE-2025-37164 network Unpatched
CVE-2025-37164networkCRITICAL 10Unpatched2026-07-06Hoverfly Middleware Command Injection to RCE (CVE-2025-54123) EPSS 11%
CVE-2025-54123 web Patched
CVE-2025-54123webCRITICAL 9.8Patched2026-07-06D-Link AX1500 SetDeviceSettings `DeviceName` OS Command Injection (CVE-2025-60854)
CVE-2025-60854 network Patched
CVE-2025-60854networkCRITICAL 9.8Patched2026-07-06TP-Link DHCP Option 66 Unauthenticated RCE — CVE-2026-11834
CVE-2026-11834 network Unverified
CVE-2026-11834networkCRITICALUnverified2026-07-05OS Command Injection in KubeAI via Model URL (CVE-2026-34940)
CVE-2026-34940 cloud Patched
CVE-2026-34940cloudHIGH 8.7Patched2026-07-05OliveTin OS Command Injection via Shell Mode Arguments (CVE-2026-27626)
CVE-2026-27626 / GHSA-49gm-hh7w-wfvf web Unverified
CVE-2026-27626 / GHSA-49gm-hh7w-wfvfwebCRITICAL 9.9Unverified2026-07-05MeiG Smart FORGE_SLT711 GoAhead Unauthenticated OS Command Injection (CVE-2026-36356) EPSS 14%
CVE-2026-36356 network Unverified
CVE-2026-36356networkCRITICALUnverified2026-07-05HAXcms Git.php OS Command Injection (CVE-2026-46394)
CVE-2026-46394 web Patched
CVE-2026-46394webHIGH 7.2Patched2026-07-05Group-Office TNEF Attachment Handler OS Command Injection (CVE-2026-25512) EPSS 19%
CVE-2026-25512 web Patched
CVE-2026-25512webCRITICAL 9.4Patched2026-07-05Gotenberg 8.29.1 Unauthenticated ExifTool Metadata Key Injection RCE (CVE-2026-42589)
CVE-2026-42589 web Patched
CVE-2026-42589webCRITICAL 9.8Patched2026-07-05FortiSandbox 4.4.0-4.4.8 — OS Command Injection via tracer-behavior Endpoint (CVE-2026-39808) KEV EPSS 93%
CVE-2026-39808 network Unverified
CVE-2026-39808networkCRITICAL 9.8Unverified2026-07-05Fortinet FortiSandbox "Start VNC" OS Command Injection (CVE-2026-25089) KEV EPSS 76%
CVE-2026-25089 network Patched
CVE-2026-25089networkCRITICAL 9.8Patched2026-07-05Coolify Authenticated Remote Command Injection via Deployment Config (CVE-2026-34038)
CVE-2026-34038 (GHSA-qqrq-r9h4-x6wp) web Patched
CVE-2026-34038webCRITICAL 10Patched2026-07-05Cockpit Unauthenticated Remote Code Execution via SSH Argument Injection (CVE-2026-4631) EPSS 15%
CVE-2026-4631 (GHSA-m4gv-x78h-3427) web Patched
CVE-2026-4631webCRITICAL 9.8Patched2026-07-05Cacti Authenticated OS Command Injection via Host Notes Variable (CVE-2026-39949)
CVE-2026-39949 web Patched
CVE-2026-39949webHIGHPatched2026-07-05