PoC Archive PoC Archive

tag

Python

WordPress Divi Ajax Filter LFI (CVE-2026-11613)
CVE-2026-11613 web Unverified
CVE-2026-11613webCRITICAL 9.8Unverified2026-09-05PaperCut MF/NG Auth Bypass + RCE Chain (CVE-2026-81578 / CVE-2026-82078)
CVE-2026-81578, CVE-2026-82078 web Unverified
CVE-2026-81578, CVE-2026-82078webCRITICAL 9.8Unverified2026-09-05Nginx HTTP/3 QUIC Pool Corruption RCE (CVE-2026-42530)
CVE-2026-42530 binary Unverified
CVE-2026-42530binaryHIGH 8.1Unverified2026-09-03Next.js Windows Cache Path Traversal RCE (CVE-2026-75604)
CVE-2026-75604 web Unverified
CVE-2026-75604webCRITICAL 9Unverified2026-09-03Kestra Authentication Bypass to RCE (CVE-2026-49869)
CVE-2026-49869, CVE-2026-53576 web Unverified
CVE-2026-49869, CVE-2026-53576webCRITICAL 10Unverified2026-09-03GitLab Unauthenticated RCE via Workhorse Pre-Auth Upload into ExifTool DjVu Injection (CVE-2021-22205) KEV RW EPSS 100%
CVE-2021-22205 (chains CVE-2021-22204 in ExifTool) web Patched
CVE-2021-22205webCRITICAL 10Patched2026-08-09CyberPanel Pre-Auth Remote Code Execution via getresetstatus Command Injection (CVE-2024-51378) KEV RW EPSS 95%
CVE-2024-51378 web Patched
CVE-2024-51378webCRITICAL 10Patched2026-08-09Check Point Security Management / Multi-Domain Server SmartConsole Authentication Bypass via Forged Application Certificate Bind (CVE-2026-16232) KEV EPSS 72%
CVE-2026-16232 network Patched
CVE-2026-16232networkCRITICAL 9.1Patched2026-08-09Crawl4AI JsonCssExtractionStrategy AST Sandbox Escape → Unauthenticated RCE (CVE-2026-53753)
CVE-2026-53753 (GHSA-qxjp-w3pj-48m7) web Patched
CVE-2026-53753webCRITICAL 9.8Patched2026-07-27XWiki SolrSearch Macro Unauthenticated Groovy RCE (CVE-2025-24893) KEV EPSS 100%
CVE-2025-24893 web Patched
CVE-2025-24893webCRITICAL 9.8Patched2026-07-06XSpeeder SXZOS Pre-Auth eval() Remote Code Execution (CVE-2025-54322) EPSS 15%
CVE-2025-54322 network Unpatched
CVE-2025-54322networkCRITICAL 10Unpatched2026-07-06Xiongmai XM530 IP Camera ONVIF Authentication Bypass (CVE-2025-65856)
CVE-2025-65856 hardware Unverified
CVE-2025-65856hardwareCRITICAL 9.8Unverified2026-07-06WP移行専用プラグイン for CPI <= 1.0.2 - Unauthenticated Arbitrary File Upload RCE (CVE-2025-11170)
CVE-2025-11170 web Unpatched
CVE-2025-11170webCRITICAL 9.8Unpatched2026-07-06WP Directory Kit Auto-Login Authentication Bypass to Full Site Takeover (CVE-2025-13390)
CVE-2025-13390 web Patched
CVE-2025-13390webCRITICAL 10Patched2026-07-06WordPress WPAMS Plugin Arbitrary File Upload to RCE (CVE-2025-39401)
CVE-2025-39401 web Unverified
CVE-2025-39401webCRITICAL 10Unverified2026-07-06WordPress Simple Link Directory Unauthenticated Password Reset to Admin Takeover (CVE-2025-49901)
CVE-2025-49901 web Patched
CVE-2025-49901webCRITICAL 9.8Patched2026-07-06WordPress Mobile Builder Plugin JWT Authentication Bypass to Admin Account Creation (CVE-2025-68860)
CVE-2025-68860 web Unpatched
CVE-2025-68860webCRITICAL 9.8Unpatched2026-07-06Wing FTP Server NULL-Byte Lua Injection Unauthenticated RCE (CVE-2025-47812) KEV EPSS 93%
CVE-2025-47812 web Patched
CVE-2025-47812webCRITICAL 10Patched2026-07-06Webkul Medical Prescription Attachment for WooCommerce — Unrestricted File Upload to Web Shell (CVE-2025-29009)
CVE-2025-29009 web Patched
CVE-2025-29009webCRITICAL 10Patched2026-07-06WavePlayer Unauthenticated Arbitrary File Upload to RCE (CVE-2025-12057)
CVE-2025-12057 web Unverified
CVE-2025-12057webCRITICAL 9.8Unverified2026-07-06TNC Toolbox: Web Performance Unauthenticated cPanel Credential Exposure (CVE-2025-12539)
CVE-2025-12539 web Patched
CVE-2025-12539webCRITICAL 10Patched2026-07-06ThingsBoard IoT Platform SSRF via SVG Image Upload (CVE-2025-34282)
CVE-2025-34282 web Patched
CVE-2025-34282webCRITICAL 9.1Patched2026-07-06Tenda AC9 `AdvSetMacMtuWan` Stack-Based Buffer Overflow (CVE-2025-29384)
CVE-2025-29384 network Unpatched
CVE-2025-29384networkCRITICAL 9.8Unpatched2026-07-06StoryChief WordPress Plugin Unauthenticated Arbitrary File Upload via Webhook (CVE-2025-7441) EPSS 39%
CVE-2025-7441 web Unpatched
CVE-2025-7441webCRITICAL 9.8Unpatched2026-07-06StoreKeeper for WooCommerce Unauthenticated Arbitrary File Upload (CVE-2025-48148) EPSS 15%
CVE-2025-48148 web Unverified
CVE-2025-48148webCRITICAL 9.8Unverified2026-07-06SmarterMail Auth Bypass via Password Reset to Pre-Auth RCE (CVE-2025-52691 / WT-2026-0001) KEV RW EPSS 86%
CVE-2025-52691 web Patched
CVE-2025-52691webCRITICAL 10Patched2026-07-06Simple User Registration WordPress Plugin — Unauthenticated Privilege Escalation (CVE-2025-4334)
CVE-2025-4334 web Unverified
CVE-2025-4334webCRITICAL 9.8Unverified2026-07-06Simple Business Directory Pro Unauthenticated Password Reset to Admin Takeover (CVE-2025-53580)
CVE-2025-53580 web Patched
CVE-2025-53580webCRITICAL 9.8Patched2026-07-06SAP NetWeaver Visual Composer Unrestricted File Upload RCE (CVE-2025-31324) KEV RW EPSS 100%
CVE-2025-31324 web Patched
CVE-2025-31324webCRITICAL 10Patched2026-07-06Samsung MagicINFO 9 Server Unauthenticated Path Traversal to RCE (CVE-2025-4632) KEV EPSS 24%
CVE-2025-4632 web Patched
CVE-2025-4632webCRITICAL 9.8Patched2026-07-06RestroPress WordPress Plugin Unauthenticated Information Exposure Leading to JWT Forgery / Account Takeover (CVE-2025-9209)
CVE-2025-9209 web Unpatched
CVE-2025-9209webCRITICAL 9.8Unpatched2026-07-06Real Spaces WordPress Theme Unauthenticated Privilege Escalation via `imic_agent_register` (CVE-2025-6758)
CVE-2025-6758 web Unverified
CVE-2025-6758webCRITICAL 9.8Unverified2026-07-06React Server Components Flight-Protocol Prototype Pollution RCE — "React2Shell" (CVE-2025-55182) KEV RW EPSS 100%
CVE-2025-55182 web Patched
CVE-2025-55182webCRITICAL 10Patched2026-07-06React Native Community CLI Metro Dev Server `/open-url` OS Command Injection (CVE-2025-11953) KEV EPSS 94%
CVE-2025-11953 network Patched
CVE-2025-11953networkCRITICAL 9.8Patched2026-07-06Python tarfile `filter="data"` Bypass via PATH_MAX/realpath Confusion (CVE-2025-4517)
CVE-2025-4517 misc Patched
CVE-2025-4517miscCRITICAL 9.4Patched2026-07-06PPOM for WooCommerce <= 33.0.15 - Unauthenticated Time-Based Blind SQL Injection (CVE-2025-11391)
CVE-2025-11391 web Patched
CVE-2025-11391webCRITICAL 9.8Patched2026-07-06Podlove Podcast Publisher <= 4.2.6 - Unauthenticated Arbitrary File Upload RCE (CVE-2025-10147)
CVE-2025-10147 web Unverified
CVE-2025-10147webCRITICAL 9.8Unverified2026-07-06pgAdmin 4 Restore Feature Regex-Bypass Command Injection RCE (CVE-2025-13780)
CVE-2025-13780 web Unverified
CVE-2025-13780webCRITICAL 9.1Unverified2026-07-06pgAdmin 4 Query Tool Authenticated eval() RCE (CVE-2025-2945) EPSS 54%
CVE-2025-2945 web Patched
CVE-2025-2945webCRITICAL 9.9Patched2026-07-06Opal Estate Pro WordPress Plugin Unauthenticated Administrator Registration (CVE-2025-6934) EPSS 25%
CVE-2025-6934 web Unverified
CVE-2025-6934webCRITICAL 9.8Unverified2026-07-06Mitel MiCollab Path Normalization Bypass to Internal Endpoints (CVE-2025-52913)
CVE-2025-52913 network Unverified
CVE-2025-52913networkCRITICAL 9.8Unverified2026-07-06Laravel Livewire Remote Code Execution via Known APP_KEY (CVE-2025-54068) KEV EPSS 96%
CVE-2025-54068 web Patched
CVE-2025-54068webCRITICAL 9.8Patched2026-07-06Langflow Pre-Auth RCE Mass Scanner (CVE-2026-27966) EPSS 34%
CVE-2026-27966 (GHSA-3645-fxcv-hqr4) web Patched
CVE-2026-27966webCRITICAL 9.8Patched2026-07-06Kubio AI Page Builder <= 2.5.1 Unauthenticated Local File Inclusion (CVE-2025-2294) EPSS 78%
CVE-2025-2294 web Unverified
CVE-2025-2294webCRITICAL 9.8Unverified2026-07-06KiotViet Sync Unauthenticated Arbitrary File Upload (CVE-2025-12674)
CVE-2025-12674 web Unverified
CVE-2025-12674webCRITICAL 9.8Unverified2026-07-06JAY Login & Register "Switch Back" Cookie Authentication Bypass (CVE-2025-14440)
CVE-2025-14440 web Unverified
CVE-2025-14440webCRITICAL 9.8Unverified2026-07-06Invision Community Theme Editor Template Injection Unauthenticated RCE (CVE-2025-47916) EPSS 84%
CVE-2025-47916 web Patched
CVE-2025-47916webCRITICAL 10Patched2026-07-06IngressNightmare: Kubernetes ingress-nginx Admission Controller Shared-Library Injection RCE (CVE-2025-1974) EPSS 100%
CVE-2025-1974 cloud Unverified
CVE-2025-1974cloudCRITICAL 9.8Unverified2026-07-06HPE OneView `id-pools/executeCommand` OS Command Injection (CVE-2025-37164) KEV EPSS 90%
CVE-2025-37164 network Unpatched
CVE-2025-37164networkCRITICAL 10Unpatched2026-07-06Hoverfly Middleware Command Injection to RCE (CVE-2025-54123) EPSS 11%
CVE-2025-54123 web Patched
CVE-2025-54123webCRITICAL 9.8Patched2026-07-06Grafana Enterprise SCIM User ID Collision / Impersonation (CVE-2025-41115) EPSS 19%
CVE-2025-41115 web Patched
CVE-2025-41115webCRITICAL 10Patched2026-07-06Gladinet CentreStack / Triofox Hardcoded AES Key Access-Ticket Forgery to Arbitrary File Read (CVE-2025-14611) KEV EPSS 53%
CVE-2025-14611 web Unverified
CVE-2025-14611webCRITICAL 9.8Unverified2026-07-06Frontend Admin by DynamiApps — Unauthenticated Administrator Account Creation (CVE-2025-13342)
CVE-2025-13342 web Patched
CVE-2025-13342webCRITICAL 9.8Patched2026-07-06Fox LMS `createOrder` Unauthenticated Privilege Escalation to Administrator (CVE-2025-14156)
CVE-2025-14156 web Unverified
CVE-2025-14156webCRITICAL 9.8Unverified2026-07-06FortiWeb `cgi-bin/fwbcgi` Path Traversal Authentication Bypass Leading to Rogue Admin Creation (CVE-2025-64446) KEV EPSS 92%
CVE-2025-64446 network Unverified
CVE-2025-64446networkCRITICAL 9.8Unverified2026-07-06Flozen WordPress Theme Unauthenticated Arbitrary File Upload (CVE-2025-49071)
CVE-2025-49071 web Unverified
CVE-2025-49071webCRITICAL 9.8Unverified2026-07-06FlowiseAI Account-Takeover via Forgot-Password Token Leak (CVE-2025-58434) EPSS 50%
CVE-2025-58434 web Patched
CVE-2025-58434webCRITICAL 9.8Patched2026-07-06Django QuerySet/Q Object SQL Injection via `_connector` Kwarg (CVE-2025-64459) EPSS 19%
CVE-2025-64459 web Patched
CVE-2025-64459webCRITICAL 9.1Patched2026-07-06DataEase PostgreSQL JDBC Datasource-Validation Bypass to Remote Code Execution (CVE-2025-49002) EPSS 47%
CVE-2025-49002 web Patched
CVE-2025-49002webCRITICAL 9.8Patched2026-07-06Crafty Controller Webhook Jinja2 Server-Side Template Injection RCE (CVE-2025-14700)
CVE-2025-14700 web Unverified
CVE-2025-14700webCRITICAL 9.9Unverified2026-07-06ConnectWise Automate Adversary-in-the-Middle Remote Code Execution (CVE-2025-11492)
CVE-2025-11492 network Patched
CVE-2025-11492networkCRITICAL 9.6Patched2026-07-06Cisco AsyncOS Spam Quarantine (TCP/6025) Exposure & IOC Scanner (CVE-2025-20393) KEV EPSS 30%
CVE-2025-20393 network Unverified
CVE-2025-20393networkCRITICAL 10Unverified2026-07-06Cisco ASA/FTD WebVPN File-Handler Heap Buffer Overflow Exposure Scanner (CVE-2025-20333) KEV EPSS 71%
CVE-2025-20333 network Unverified
CVE-2025-20333networkCRITICAL 9.9Unverified2026-07-06Cibeles AI `actualizador_git.php` Unauthenticated Arbitrary File Upload / RCE (CVE-2025-13595)
CVE-2025-13595 web Unverified
CVE-2025-13595webCRITICAL 9.8Unverified2026-07-06ASP.NET Core Kestrel HTTP Request Smuggling (CVE-2025-55315) EPSS 66%
CVE-2025-55315 network Patched
CVE-2025-55315networkCRITICAL 9.9Patched2026-07-06AI Feeds `actualizador_git.php` Unauthenticated Arbitrary File Upload / RCE (CVE-2025-13597)
CVE-2025-13597 web Unverified
CVE-2025-13597webCRITICAL 9.8Unverified2026-07-06AI Engine WordPress Plugin Unauthenticated MCP Token Disclosure to Admin Account Creation (CVE-2025-11749) EPSS 75%
CVE-2025-11749 web Unverified
CVE-2025-11749webCRITICAL 9.8Unverified2026-07-06Adobe Magento "SessionReaper" Unauthenticated File Upload / LFI (CVE-2025-54236) KEV EPSS 95%
CVE-2025-54236 web Patched
CVE-2025-54236webCRITICAL 9.1Patched2026-07-06Adobe Experience Manager Forms XXE to JNDI RCE Scanner (CVE-2025-54253) KEV EPSS 88%
CVE-2025-54253 web Unverified
CVE-2025-54253webCRITICAL 10Unverified2026-07-06ACF Extended (ACFE) `prepare_form()` Unauthenticated RCE via Privilege Escalation (CVE-2025-13486) EPSS 68%
CVE-2025-13486 web Unverified
CVE-2025-13486webCRITICAL 9.8Unverified2026-07-06"Grocery" PHP Application `search_products_itname.php` `sitem_name` Boolean-Based SQL Injection (CVE-2025-65354)
CVE-2025-65354 web Unpatched
CVE-2025-65354webCRITICAL 9.8Unpatched2026-07-06YAMCS LdapAuthModule LDAP Injection Authentication Bypass (CVE-2026-42568)
CVE-2026-42568 / GHSA-cqh3-jg8p-336j network Patched
CVE-2026-42568 / GHSA-cqh3-jg8p-336jnetworkMEDIUMPatched2026-07-05Weblate Arbitrary File Read via ssh-keyscan Host Argument Injection — CVE-2026-24126
CVE-2026-24126 web Patched
CVE-2026-24126webHIGH 6.5Patched2026-07-05Vendure GraphQL Admin API Authentication Timing Attack / User Enumeration (CVE-2026-25050)
CVE-2026-25050 web Patched
CVE-2026-25050webMEDIUMPatched2026-07-05The Events Calendar WordPress Plugin Unauthenticated Blind SQL Injection (CVE-2026-49772)
CVE-2026-49772 web Patched
CVE-2026-49772webCRITICAL 9.3Patched2026-07-05Splunk Secure Gateway jsonpickle Deserialization RCE (CVE-2026-20251) EPSS 32%
CVE-2026-20251 web Unverified
CVE-2026-20251webHIGH 8.8Unverified2026-07-05Sparx Enterprise Architect / Pro Cloud Server Unauthenticated Binary-Protocol SQL Injection (CVE-2026-42096)
CVE-2026-42096 network Unverified
CVE-2026-42096networkCRITICALUnverified2026-07-05Rocket.Chat OAuth2 NoSQL Injection Privilege Escalation — CVE-2026-29198
CVE-2026-29198 web Patched
CVE-2026-29198webCRITICALPatched2026-07-05pypdf Circular Outline Reference Infinite-Loop DoS (CVE-2026-24688)
CVE-2026-24688 misc Patched
CVE-2026-24688miscHIGHPatched2026-07-05Prefect GitRepository Git Argument Injection RCE via `commit_sha` — CVE-2026-5366
CVE-2026-5366 (Huntr bounty e2e88a0f-a8f6-49c9-94c5-e98dc385f07a) web Patched
CVE-2026-5366webHIGHPatched2026-07-05PraisonAI API Server Missing Authentication (CVE-2026-44338) EPSS 29%
CVE-2026-44338 / [GHSA-6rmh-7xcm-cpxj](https://github.com/MervinPraison/PraisonAI/security/advisories/GHSA-6rmh-7xcm-cpxj) web Patched
CVE-2026-44338 / [GHSA-6rmh-7xcm-cpxj]webHIGHPatched2026-07-05phpVMS Unauthenticated Legacy Importer Database Wipe (CVE-2026-42569)
CVE-2026-42569 web Patched
CVE-2026-42569webCRITICALPatched2026-07-05Ormar ORM SQL Injection via min()/max() Aggregate Methods (CVE-2026-26198)
CVE-2026-26198 (GHSA-xxh2-68g9-8jqr) web Patched
CVE-2026-26198webCRITICAL 9.8Patched2026-07-05MindsDB — Handler Path Traversal to Remote Code Execution (CVE-2026-27483) EPSS 11%
CVE-2026-27483 web Patched
CVE-2026-27483webCRITICALPatched2026-07-05Microsoft Semantic Kernel In-Memory Vector Store Filter eval() Sandbox Bypass RCE (CVE-2026-26030)
CVE-2026-26030 misc Patched
CVE-2026-26030miscCRITICALPatched2026-07-05Malicious DOCX/OLE CLSID Object Embedding Builder (CVE-2026-21509) KEV EPSS 73%
CVE-2026-21509 misc Unverified
CVE-2026-21509miscHIGHUnverified2026-07-05MagicMirror² Unauthenticated SSRF via `/cors` Endpoint (CVE-2026-42281)
CVE-2026-42281 web Patched
CVE-2026-42281webCRITICAL 9.2Patched2026-07-05LiteLLM Proxy Unauthenticated Auth Bypass via Host-Header Route Confusion (CVE-2026-49468)
CVE-2026-49468 web Patched
CVE-2026-49468webCRITICAL 9.8Patched2026-07-05LatePoint Calendar Booking Plugin Contributor-to-Administrator Privilege Escalation (CVE-2026-49083)
CVE-2026-49083 web Unverified
CVE-2026-49083webHIGH 8.8Unverified2026-07-05Langflow Unauthenticated Remote Code Execution via `validate/code` Endpoint (CVE-2026-0770) KEV EPSS 63%
CVE-2026-0770 web Patched
CVE-2026-0770webCRITICALPatched2026-07-05KnowledgeDeliver ASP.NET ViewState Deserialization RCE via Hardcoded Machine Keys — CVE-2026-5426
CVE-2026-5426 web Unverified
CVE-2026-5426webCRITICALUnverified2026-07-05JupyterHub Cross-Origin Form POST XSRF Bypass (CVE-2026-40864)
CVE-2026-40864 (GHSA-m68r-v472-jgq9) web Patched
CVE-2026-40864webMEDIUMPatched2026-07-05Flowise NVIDIA NIM Endpoint Authentication Bypass — CVE-2026-30824 EPSS 36%
CVE-2026-30824 web Patched
CVE-2026-30824webCRITICAL 9.8Patched2026-07-05EspoCRM 9.3.3 Authenticated SSRF via Alternative IPv4 Loopback Notation — CVE-2026-33534
CVE-2026-33534 web Patched
CVE-2026-33534webMEDIUMPatched2026-07-05docling-core Unsafe YAML Deserialization Leading to Code Execution — CVE-2026-24009
CVE-2026-24009 misc Patched
CVE-2026-24009miscHIGHPatched2026-07-05Django MultiPartParser Base64 Whitespace CPU Amplification DoS — CVE-2026-33033
CVE-2026-33033 web Patched
CVE-2026-33033webMEDIUMPatched2026-07-05Django GIS RasterField SQL Injection (CVE-2026-1207) EPSS 13%
CVE-2026-1207 web Patched
CVE-2026-1207webHIGHPatched2026-07-05ChatterBot Denial of Service via SQLAlchemy Connection Pool Exhaustion (CVE-2026-23842)
CVE-2026-23842 misc Patched
CVE-2026-23842miscHIGH 7.5Patched2026-07-05Budibase Authentication Bypass to Plugin-Upload Reverse Shell — CVE-2026-31816 EPSS 15%
CVE-2026-31816 web Unverified
CVE-2026-31816webCRITICALUnverified2026-07-05AutoGPT Platform Chat Session IDOR / Session Hijack — CVE-2026-30950
CVE-2026-30950 (GHSA-q58p-v9r9-7gqj) web Patched
CVE-2026-30950webHIGH 7.1Patched2026-07-05Apache Superset Authenticated SQL Injection via sqlExpression/where Bypass — CVE-2026-23980
CVE-2026-23980 web Patched
CVE-2026-23980webMEDIUM 6.5Patched2026-07-05AI Model-Loader `trust_remote_code` Order-of-Operations RCE Simulation (CVE-2026-22807)
CVE-2026-22807 misc Patched
CVE-2026-22807miscHIGHPatched2026-07-05Pillow ImageCms Mutable output_mode Heap OOB Write
None assigned as of 2026-07-03 binary Unverified
None assigned as of 2026-07-03binaryHIGHUnverified2026-07-03SP Page Builder (Joomla) Unauthenticated File Upload RCE (CVE-2026-48908) KEV EPSS 15%
CVE-2026-48908 (GHSA-8fwr-8fxr-8v2p) web Patched
CVE-2026-48908webCRITICAL 10Patched2026-06-30GNU Inetutils telnetd Unauthenticated Root RCE via NEW-ENVIRON (CVE-2026-24061) KEV EPSS 98%
CVE-2026-24061 network Patched
CVE-2026-24061networkCRITICAL 9.8Patched2026-06-30GeoVision GV-I/O Box 4E DVRSearch Unauthenticated Stack Buffer Overflow RCE (CVE-2026-12485)
CVE-2026-12485 network Patched
CVE-2026-12485networkCRITICAL 10Patched2026-06-30FFmpeg MagicYUV Decoder Out-of-Bounds Write / RCE — PixelSmash (CVE-2026-8461)
CVE-2026-8461 binary Patched
CVE-2026-8461binaryHIGH 8.8Patched2026-06-30Copy Fail Linux Kernel Local Privilege Escalation (CVE-2026-31431) KEV EPSS 100%
CVE-2026-31431 binary Patched
CVE-2026-31431binaryHIGHPatched2026-05-17