PoC Archive PoC Archive

tag

Jsp-Webshell

  • CVE-2025-31324 web CRITICAL 10 KEV Ransomware EPSS 100%

    SAP NetWeaver Visual Composer Unrestricted File Upload RCE (CVE-2025-31324)

    CVE-2025-31324 is an unrestricted file upload vulnerability in the Metadata Uploader servlet of SAP NetWeaver Visual Composer (VCFRAMEWORK), which is exposed unauthenticated on the /developmentserver/metadatauploader endpoint. The root cause is that this…

    Patched 2026-07-06
  • CVE-2025-4632 web CRITICAL 9.8 KEV EPSS 24%

    Samsung MagicINFO 9 Server Unauthenticated Path Traversal to RCE (CVE-2025-4632)

    Samsung MagicINFO 9 Server's SWUpdateFileUploader servlet, which handles firmware/content update uploads from signage devices, fails to properly sanitize the fileName parameter, allowing directory traversal sequences (../../) to break out of the intended…

    Patched 2026-07-06
  • CVE-2026-20230 network CRITICAL 8.6 KEV EPSS 83%

    Cisco Unified CM WebDialer SSRF to Arbitrary File Write / RCE (CVE-2026-20230)

    CVE-2026-20230 is a critical server-side request forgery vulnerability in Cisco Unified CM / Unified CM SME caused by improper input validation of HTTP requests processed by the WebDialer component. A remote unauthenticated attacker can chain unauthenticated…

    Unverified 2026-07-01