PoC Archive PoC Archive

tag

Ldap

  • CVE-2026-25177 network HIGH 8.8

    Active Directory — SPN Unicode Collision Detection Scanner (CVE-2026-25177)

    CVE-2026-25177 is a privilege escalation vulnerability in Active Directory Domain Services caused by improper restriction of Unicode characters in Service Principal Names (SPNs). An authenticated user with write-SPN permissions can inject Unicode zero-width…

    Patched 2026-08-11
  • CVE-2025-54253 web CRITICAL 10 KEV EPSS 88%

    Adobe Experience Manager Forms XXE to JNDI RCE Scanner (CVE-2025-54253)

    AEM Forms exposes several form-submission endpoints (e.g. /content/forms/af/submit, /services/SubmitForm, /bin/receive, /lc/submit) that parse attacker-supplied XML without disabling external entity resolution. The root cause is an XML parser configured to…

    Unverified 2026-07-06
  • CVE-2026-42568 / GHSA-cqh3-jg8p-336j network MEDIUM

    YAMCS LdapAuthModule LDAP Injection Authentication Bypass (CVE-2026-42568)

    YAMCS's LdapAuthModule builds LDAP search filters by directly substituting the user-supplied username into a filter template (e.g. (uid={0})) without RFC 4515 escaping. An attacker can supply LDAP metacharacters in the username field to alter the filter's…

    Patched 2026-07-05
  • CVE-2024-49113 network CRITICAL EPSS 83%

    LDAP Nightmare — Windows LDAP Client RCE/DoS (CVE-2024-49113)

    LDAP Nightmare is a public PoC for CVE-2024-49113, a critical vulnerability in Windows LDAP client behavior that can be reached through Netlogon workflow interactions. The PoC starts a malicious LDAP service and triggers victim-side LDAP resolution via…

    Patched 2026-05-15