PoC Archive PoC Archive

tag

Ransomware

Oracle E-Business Suite Pre-Authentication RCE Chain (CVE-2025-61882) KEV RW EPSS 100%
CVE-2025-61882 (Oracle Security Alert, out-of-band, October 2025) web Patched
CVE-2025-61882webCRITICAL 9.8Patched2026-08-09Ivanti Endpoint Manager Mobile (EPMM) Unauthenticated Remote API Access (CVE-2023-35078) KEV RW EPSS 100%
CVE-2023-35078 (Ivanti advisory; CWE-287 per NVD) network Unverified
CVE-2023-35078networkCRITICAL 9.8Unverified2026-08-09Ivanti Connect Secure / Policy Secure / ZTA Gateways Remote Unauthenticated Stack-Based Buffer Overflow (CVE-2025-22457) KEV RW EPSS 100%
CVE-2025-22457 network Unpatched
CVE-2025-22457networkCRITICAL 9Unpatched2026-08-09GitLab Unauthenticated RCE via Workhorse Pre-Auth Upload into ExifTool DjVu Injection (CVE-2021-22205) KEV RW EPSS 100%
CVE-2021-22205 (chains CVE-2021-22204 in ExifTool) web Patched
CVE-2021-22205webCRITICAL 10Patched2026-08-09CyberPanel Pre-Auth Remote Code Execution via getresetstatus Command Injection (CVE-2024-51378) KEV RW EPSS 95%
CVE-2024-51378 web Patched
CVE-2024-51378webCRITICAL 10Patched2026-08-09SimpleHelp OIDC Authentication Bypass via Unverified JWT Signature (CVE-2026-48558) KEV EPSS 12%
CVE-2026-48558 web Patched
CVE-2026-48558webCRITICAL 10Patched2026-07-19Fortinet FortiClient EMS Pre-Auth Bypass — "FortiBleed" (CVE-2026-35616) KEV EPSS 91%
CVE-2026-35616 network Patched
CVE-2026-35616networkCRITICAL 9.1Patched2026-07-03Check Point Remote Access VPN IKEv1 Auth Bypass (CVE-2026-50751) KEV RW EPSS 84%
CVE-2026-50751 network Patched
CVE-2026-50751networkCRITICAL 9.3Patched2026-06-28ToolShell - SharePoint Unauthenticated RCE Chain KEV RW EPSS 100%
CVE-2025-53770, CVE-2025-53771, CVE-2025-49704, CVE-2025-49706 web Patched
CVE-2025-53770, CVE-2025-53771, CVE-2025-49704, CVE-2025-49706webCRITICALPatched2026-05-17Linux nf_tables Use-After-Free Local Privilege Escalation (CVE-2024-1086) KEV RW EPSS 28%
CVE-2024-1086 binary Patched
CVE-2024-1086binaryHIGH 7.8Patched2026-05-17Confluence SSTI RCE - CVE-2023-22527 KEV RW EPSS 100%
CVE-2023-22527 web Patched
CVE-2023-22527webCRITICAL 10Patched2026-05-17VMware ESXi Active Directory Authentication Bypass (CVE-2024-37085) KEV RW EPSS 27%
CVE-2024-37085 network Patched
CVE-2024-37085networkMEDIUM 6.8Patched2026-05-16