PoC Archive PoC Archive

tag

Pre-Auth

WordPress — Pre-Auth XSS to RCE Chain via Login Page Parser Differential (CVE-2026-64638, "XSS2Shell") EPSS 31%
CVE-2026-64638 web Unverified
CVE-2026-64638webHIGH 8.9Unverified2026-08-09Oracle E-Business Suite Pre-Authentication RCE Chain (CVE-2025-61882) KEV RW EPSS 100%
CVE-2025-61882 (Oracle Security Alert, out-of-band, October 2025) web Patched
CVE-2025-61882webCRITICAL 9.8Patched2026-08-09XSpeeder SXZOS Pre-Auth eval() Remote Code Execution (CVE-2025-54322) EPSS 15%
CVE-2025-54322 network Unpatched
CVE-2025-54322networkCRITICAL 10Unpatched2026-07-06SmarterMail Auth Bypass via Password Reset to Pre-Auth RCE (CVE-2025-52691 / WT-2026-0001) KEV RW EPSS 86%
CVE-2025-52691 web Patched
CVE-2025-52691webCRITICAL 10Patched2026-07-06Monsta FTP Pre-Authentication Remote Code Execution via Arbitrary File Upload (CVE-2025-34299) EPSS 73%
CVE-2025-34299 network Patched
CVE-2025-34299networkCRITICAL 9.8Patched2026-07-06Langflow Pre-Auth RCE Mass Scanner (CVE-2026-27966) EPSS 34%
CVE-2026-27966 (GHSA-3645-fxcv-hqr4) web Patched
CVE-2026-27966webCRITICAL 9.8Patched2026-07-06strongSwan RADIUS Attribute-Iterator Pre-Auth Infinite Loop / Remote DoS (CVE-2026-35333)
CVE-2026-35333 network Unverified
CVE-2026-35333networkMEDIUMUnverified2026-07-05OpenAM Pre-Authentication RCE via `jato.clientSession` Deserialization (CVE-2026-33439) EPSS 10%
CVE-2026-33439 web Patched
CVE-2026-33439webCRITICAL 9.8Patched2026-07-05NVIDIA Triton Inference Server SageMaker Auth Bypass to Unauthenticated RCE (CVE-2026-24207)
CVE-2026-24207 (sibling: CVE-2026-24206, Vertex AI, analysis only) network Patched
CVE-2026-24207networkCRITICAL 9.8Patched2026-07-05MIPS-Based Managed Switch Firmware Pre-Auth Kernel RCE — CVE-2026-1668
CVE-2026-1668 binary Unverified
CVE-2026-1668binaryCRITICALUnverified2026-07-05GNU InetUtils telnetd LINEMODE SLC Pre-Auth Buffer Overflow (CVE-2026-32746) EPSS 24%
CVE-2026-32746 network Unverified
CVE-2026-32746networkCRITICAL 9.8Unverified2026-07-05Discuz! X5.0 Race Condition + CAPTCHA-Solving Pre-Auth to RCE Chain (CVE-2026-49952)
CVE-2026-49952 (chain also referenced as KIS-2026-09, KIS-2026-10, KIS-2026-11) web Unverified
CVE-2026-49952webCRITICALUnverified2026-07-05Splunk Enterprise Pre-Auth RCE via PostgreSQL Sidecar (CVE-2026-20253) KEV EPSS 97%
CVE-2026-20253 web Patched
CVE-2026-20253webCRITICALPatched2026-06-28Ivanti Sentry Pre-Auth RCE + Auth Bypass (CVE-2026-10520 / CVE-2026-10523) KEV EPSS 100%
CVE-2026-10520, CVE-2026-10523 network Patched
CVE-2026-10520, CVE-2026-10523networkCRITICAL 10Patched2026-06-28Next.js RSC Server-Action DoS via Flight Deserialization (CVE-2026-23870)
CVE-2026-23870 web Patched
CVE-2026-23870webHIGH 7.5Patched2026-05-17Ivanti Connect Secure Pre-Auth RCE (Stack Overflow) KEV RW EPSS 100%
CVE-2025-0282 network Unverified
CVE-2025-0282networkCRITICAL 9Unverified2026-05-17Erlang/OTP SSH Pre-Auth RCE - CVE-2025-32433 KEV EPSS 99%
CVE-2025-32433 network Patched
CVE-2025-32433networkCRITICAL 10Patched2026-05-17Apache httpd mod_http2 Double-Free Pre-Auth RCE - CVE-2026-23918 EPSS 50%
CVE-2026-23918 web Patched
CVE-2026-23918webCRITICALPatched2026-05-17