PoC Archive PoC Archive

tag

Kev

UniFi OS -- Unauthenticated Command Injection RCE (CVE-2026-34910) KEV EPSS 87%
CVE-2026-34910, CVE-2026-34909, CVE-2026-34908 network Patched
CVE-2026-34910, CVE-2026-34909, CVE-2026-34908networkCRITICAL 10Patched2026-08-16GitLab Unauthenticated RCE via Workhorse Pre-Auth Upload into ExifTool DjVu Injection (CVE-2021-22205) KEV RW EPSS 100%
CVE-2021-22205 (chains CVE-2021-22204 in ExifTool) web Patched
CVE-2021-22205webCRITICAL 10Patched2026-08-09CyberPanel Pre-Auth Remote Code Execution via getresetstatus Command Injection (CVE-2024-51378) KEV RW EPSS 95%
CVE-2024-51378 web Patched
CVE-2024-51378webCRITICAL 10Patched2026-08-09Microsoft SharePoint Server WS-Federation SecurityContextToken Deserialization → Unauthenticated RCE (CVE-2026-50522) KEV EPSS 85%
CVE-2026-50522 web Patched
CVE-2026-50522webCRITICAL 9.8Patched2026-07-27Joomla Balbooa Forms Unauthenticated Arbitrary File Upload → RCE (CVE-2026-56291) KEV EPSS 15%
CVE-2026-56291 web Unverified
CVE-2026-56291webCRITICAL 9.8Unverified2026-07-27SimpleHelp OIDC Authentication Bypass via Unverified JWT Signature (CVE-2026-48558) KEV EPSS 12%
CVE-2026-48558 web Patched
CVE-2026-48558webCRITICAL 10Patched2026-07-19Langflow Responses API IDOR — Execute Another User's Flow (CVE-2026-55255) KEV
CVE-2026-55255 (GHSA-qrpv-q767-xqq2) web Patched
CVE-2026-55255webHIGH 8.4Patched2026-07-19Cisco Unified Communications Manager WebDialer SSRF → Arbitrary File Write → Root (CVE-2026-20230) KEV EPSS 88%
CVE-2026-20230 (cisco-sa-cucm-ssrf-cXPnHcW) network Patched
CVE-2026-20230networkCRITICAL 8.6Patched2026-07-19Adobe ColdFusion RDS Path Traversal → Arbitrary File Read/Write → RCE (CVE-2026-48282) KEV EPSS 42%
CVE-2026-48282 (Adobe APSB26-68) web Patched
CVE-2026-48282webCRITICAL 10Patched2026-07-19SonicWall SMA1000 WorkPlace SSRF → Internal Erlang RPC Remote Code Execution (CVE-2026-15409) KEV RW EPSS 84%
CVE-2026-15409 (SNWLID-2026-0008) network Patched
CVE-2026-15409networkCRITICAL 10Patched2026-07-15ZKTeco BioTime v8.5.5 Unauthenticated Path Traversal / Arbitrary File Read via iclock API (CVE-2023-38950) KEV EPSS 85%
CVE-2023-38950 web Patched
CVE-2023-38950webHIGH 7.5Patched2026-07-11Unauthenticated Arbitrary File Upload RCE in iCagenda for Joomla (CVE-2026-48939) KEV EPSS 20%
CVE-2026-48939 web Patched
CVE-2026-48939webCRITICAL 9.8Patched2026-07-11Sitecore XP Report.ashx Insecure Deserialization RCE (CVE-2021-42237) KEV RW EPSS 98%
CVE-2021-42237 (Sitecore advisory SC2021-003-499266) web Patched
CVE-2021-42237webCRITICAL 9.8Patched2026-07-11Nagios XI 5.5.6–5.7.5 Authenticated OS Command Injection — Windows WMI Config Wizard (CVE-2021-25296) KEV EPSS 72%
CVE-2021-25296 web Patched
CVE-2021-25296webHIGH 8.8Patched2026-07-11Nagios XI 5.5.6–5.7.5 Authenticated OS Command Injection — Switch Config Wizard (CVE-2021-25297) KEV EPSS 57%
CVE-2021-25297 web Patched
CVE-2021-25297webHIGH 8.8Patched2026-07-11Nagios XI 5.5.6–5.7.5 Authenticated OS Command Injection — Cloud-VM Config Wizard (CVE-2021-25298) KEV EPSS 75%
CVE-2021-25298 web Patched
CVE-2021-25298webHIGH 8.8Patched2026-07-11D-Link DIR-820L `get_set.ccp` LAN Configuration OS Command Injection (CVE-2022-26258) KEV EPSS 80%
CVE-2022-26258 network Unverified
CVE-2022-26258networkCRITICAL 9.8Unverified2026-07-11Monsta FTP Pre-Authentication Remote Code Execution via Arbitrary File Upload (CVE-2025-34299) EPSS 73%
CVE-2025-34299 network Patched
CVE-2025-34299networkCRITICAL 9.8Patched2026-07-06FortiSandbox 4.4.0-4.4.8 — OS Command Injection via tracer-behavior Endpoint (CVE-2026-39808) KEV EPSS 93%
CVE-2026-39808 network Unverified
CVE-2026-39808networkCRITICAL 9.8Unverified2026-07-05SP Page Builder (Joomla) Unauthenticated File Upload RCE (CVE-2026-48908) KEV EPSS 15%
CVE-2026-48908 (GHSA-8fwr-8fxr-8v2p) web Patched
CVE-2026-48908webCRITICAL 10Patched2026-06-30Jenkins CLI Arbitrary File Read to RCE (CVE-2024-23897) KEV RW EPSS 100%
CVE-2024-23897 web Patched
CVE-2024-23897webCRITICAL 9.8Patched2026-05-17Fortinet FortiManager FortiJump Unauthenticated RCE (CVE-2024-47575) KEV EPSS 95%
CVE-2024-47575 network Unverified
CVE-2024-47575networkCRITICAL 9.8Unverified2026-05-17VMware vCenter Server DCE/RPC Heap Overflow RCE (CVE-2024-37079) KEV EPSS 22%
CVE-2024-37079 network Patched
CVE-2024-37079networkCRITICAL 9.8Patched2026-05-16Fortinet FortiOS SSL VPN Unauthenticated RCE (CVE-2024-21762) KEV RW EPSS 84%
CVE-2024-21762 web Patched
CVE-2024-21762webCRITICAL 9.6Patched2026-05-16Fortinet FortiOS / FortiProxy Authentication Bypass (CVE-2024-55591) KEV RW EPSS 98%
CVE-2024-55591 (Fortinet FG-IR-24-535) web Unverified
CVE-2024-55591webCRITICAL 9.6Unverified2026-05-16