PoC Archive PoC Archive

tag

Cwe-863

Real Spaces WordPress Theme Unauthenticated Privilege Escalation via `imic_agent_register` (CVE-2025-6758)
CVE-2025-6758 web Unverified
CVE-2025-6758webCRITICAL 9.8Unverified2026-07-06FreePBX Framework Module Authentication Bypass via Forged Authorization Header (CVE-2025-66039)
CVE-2025-66039 network Patched
CVE-2025-66039networkCRITICAL 9.8Patched2026-07-06LiteLLM Proxy Privilege Escalation via `/user/update` (CVE-2026-47102)
CVE-2026-47102 web Patched
CVE-2026-47102webHIGH 8.8Patched2026-07-05LiteLLM /config/update Broken Access Control (CVE-2026-35029) EPSS 26%
CVE-2026-35029 web Patched
CVE-2026-35029webHIGH 8.8Patched2026-07-05Kanboard — Missing Access Control on Plugin Installation Leads to Administrative RCE via Webshell Plugin (CVE-2026-25924)
CVE-2026-25924 / GHSA-grch-p7vf-vc4f web Patched
CVE-2026-25924 / GHSA-grch-p7vf-vc4fwebHIGH 8.4Patched2026-07-05Gitea OAuth2 Scope Enforcement Bypass via HTTP Basic Auth — CVE-2026-28699
CVE-2026-28699 web Patched
CVE-2026-28699webHIGHPatched2026-07-05