PoC Archive PoC Archive

tag

Post-Auth

  • CVE-2025-49113 web CRITICAL 9.9 KEV EPSS 98%

    Roundcube Webmail Post-Auth RCE via PHP Object Deserialization (CVE-2025-49113)

    Roundcube Webmail versions up to and including 1.6.10 are vulnerable to a post-authentication PHP object deserialization vulnerability in the file upload handler, which passes a client-supplied attachment filename through a deserialization path without…

    Patched 2026-07-06
  • CVE-2024-21683 web HIGH 8.3 EPSS 88%

    Confluence Post-Auth RCE - CVE-2024-21683

    CVE-2024-21683 is an authenticated Remote Code Execution vulnerability in Atlassian Confluence Data Center and Server affecting the "Add a New Language" feature in the Code Macro plugin. An authenticated Confluence administrator can upload a malicious .js…

    Unverified 2026-05-17