PoC Archive PoC Archive

tag

Os-Command-Injection

Nagios XI 5.5.6–5.7.5 Authenticated OS Command Injection — Windows WMI Config Wizard (CVE-2021-25296) KEV EPSS 72%
CVE-2021-25296 web Patched
CVE-2021-25296webHIGH 8.8Patched2026-07-11Nagios XI 5.5.6–5.7.5 Authenticated OS Command Injection — Switch Config Wizard (CVE-2021-25297) KEV EPSS 57%
CVE-2021-25297 web Patched
CVE-2021-25297webHIGH 8.8Patched2026-07-11Nagios XI 5.5.6–5.7.5 Authenticated OS Command Injection — Cloud-VM Config Wizard (CVE-2021-25298) KEV EPSS 75%
CVE-2021-25298 web Patched
CVE-2021-25298webHIGH 8.8Patched2026-07-11D-Link AX1500 SetDeviceSettings `DeviceName` OS Command Injection (CVE-2025-60854)
CVE-2025-60854 network Patched
CVE-2025-60854networkCRITICAL 9.8Patched2026-07-06FortiSandbox 4.4.0-4.4.8 — OS Command Injection via tracer-behavior Endpoint (CVE-2026-39808) KEV EPSS 93%
CVE-2026-39808 network Unverified
CVE-2026-39808networkCRITICAL 9.8Unverified2026-07-05Dolibarr ERP/CRM OS Command Injection via MAIN_ODT_AS_PDF (CVE-2026-23500)
CVE-2026-23500 / GHSA-w5j3-8fcr-h87w web Patched
CVE-2026-23500 / GHSA-w5j3-8fcr-h87wwebCRITICALPatched2026-07-05Ivanti Sentry Pre-Auth RCE + Auth Bypass (CVE-2026-10520 / CVE-2026-10523) KEV EPSS 100%
CVE-2026-10520, CVE-2026-10523 network Patched
CVE-2026-10520, CVE-2026-10523networkCRITICAL 10Patched2026-06-28