PoC Archive PoC Archive

tag

RCE

PaperCut MF/NG Auth Bypass + RCE Chain (CVE-2026-81578 / CVE-2026-82078)
CVE-2026-81578, CVE-2026-82078 web Unverified
CVE-2026-81578, CVE-2026-82078webCRITICAL 9.8Unverified2026-09-05WP Cookie Notice Unauthenticated File Upload RCE (CVE-2026-82970)
CVE-2026-82970 web Unverified
CVE-2026-82970webCRITICAL 10Unverified2026-09-03Nginx HTTP/3 QUIC Pool Corruption RCE (CVE-2026-42530)
CVE-2026-42530 binary Unverified
CVE-2026-42530binaryHIGH 8.1Unverified2026-09-03Next.js Windows Cache Path Traversal RCE (CVE-2026-75604)
CVE-2026-75604 web Unverified
CVE-2026-75604webCRITICAL 9Unverified2026-09-03Kestra Authentication Bypass to RCE (CVE-2026-49869)
CVE-2026-49869, CVE-2026-53576 web Unverified
CVE-2026-49869, CVE-2026-53576webCRITICAL 10Unverified2026-09-03Chrome V8 Type Confusion RCE (CVE-2026-5865)
CVE-2026-5865 binary Unverified
CVE-2026-5865binaryHIGH 8.8Unverified2026-09-03UniFi OS -- Unauthenticated Command Injection RCE (CVE-2026-34910) KEV EPSS 87%
CVE-2026-34910, CVE-2026-34909, CVE-2026-34908 network Patched
CVE-2026-34910, CVE-2026-34909, CVE-2026-34908networkCRITICAL 10Patched2026-08-16PHP bcmath bccomp() Out-of-Bounds Write (CVE-2026-17544)
CVE-2026-17544 / GHSA-x692-q9x7-8c3f web Unverified
CVE-2026-17544 / GHSA-x692-q9x7-8c3fwebCRITICAL 9.8Unverified2026-08-16nginx PCRE Capture Variable Heap Overflow to Pre-Auth RCE (CVE-2026-42533)
CVE-2026-42533 web Patched
CVE-2026-42533webCRITICAL 9.8Patched2026-08-16Citrix NetScaler ADC/Gateway -- Pre-Auth SAML PrefixList Heap Overflow to RCE (CVE-2026-8452) KEV
CVE-2026-8452 network Patched
CVE-2026-8452networkCRITICAL 9.8Patched2026-08-16Cisco IMC Argument Injection to Root RCE (CVE-2026-20200)
CVE-2026-20200 / NSIDE-SA-2026-003 network Patched
CVE-2026-20200 / NSIDE-SA-2026-003networkCRITICAL 9.9Patched2026-08-16Microsoft SCCM — AdminService CAB Extraction Path-Traversal to SYSTEM RCE (CVE-2026-47301)
CVE-2026-47301 network Unverified
CVE-2026-47301networkCRITICAL 9.8Unverified2026-08-15WordPress — Pre-Auth XSS to RCE Chain via Login Page Parser Differential (CVE-2026-64638, "XSS2Shell") EPSS 31%
CVE-2026-64638 web Unverified
CVE-2026-64638webHIGH 8.9Unverified2026-08-09Oracle E-Business Suite Pre-Authentication RCE Chain (CVE-2025-61882) KEV RW EPSS 100%
CVE-2025-61882 (Oracle Security Alert, out-of-band, October 2025) web Patched
CVE-2025-61882webCRITICAL 9.8Patched2026-08-09MariaDB — Low-Privilege Remote Code Execution via ST_Area OOB Read + SYS_REFCURSOR Use-After-Free
MDEV-40328 (ST_Area OOB read); cursor-array UAF has no assigned CVE yet binary Unpatched
MDEV-40328binaryCRITICAL 8.8Unpatched2026-08-09Ivanti Connect Secure / Policy Secure / ZTA Gateways Remote Unauthenticated Stack-Based Buffer Overflow (CVE-2025-22457) KEV RW EPSS 100%
CVE-2025-22457 network Unpatched
CVE-2025-22457networkCRITICAL 9Unpatched2026-08-09GitLab Unauthenticated RCE via Workhorse Pre-Auth Upload into ExifTool DjVu Injection (CVE-2021-22205) KEV RW EPSS 100%
CVE-2021-22205 (chains CVE-2021-22204 in ExifTool) web Patched
CVE-2021-22205webCRITICAL 10Patched2026-08-09CyberPanel Pre-Auth Remote Code Execution via getresetstatus Command Injection (CVE-2024-51378) KEV RW EPSS 95%
CVE-2024-51378 web Patched
CVE-2024-51378webCRITICAL 10Patched2026-08-09IBM Langflow OSS Unauthenticated RCE via Auto-Login + validate/code Chain (CVE-2026-9198) KEV EPSS 35%
CVE-2026-9198 web Patched
CVE-2026-9198webCRITICAL 9.8Patched2026-07-31Craft CMS Pre-Auth Remote Code Execution via Session Poisoning + Yii2 PhpManager Gadget (CVE-2025-32432) KEV EPSS 100%
CVE-2025-32432 web Patched
CVE-2025-32432webCRITICAL 10Patched2026-07-31Alibaba Fastjson 1.x checkAutoType Bypass to Remote Code Execution via jar:http SSRF and fd-Reread Trick (CVE-2026-16723) EPSS 16%
CVE-2026-16723 web Unpatched
CVE-2026-16723webCRITICAL 9Unpatched2026-07-31Rails Active Storage Arbitrary File Read to RCE via libvips Unfuzzed Loaders (CVE-2026-66066) EPSS 28%
CVE-2026-66066 (GHSA-xr9x-r78c-5hrm) web Patched
CVE-2026-66066webCRITICAL 9.5Patched2026-07-27Microsoft SharePoint Server WS-Federation SecurityContextToken Deserialization → Unauthenticated RCE (CVE-2026-50522) KEV EPSS 85%
CVE-2026-50522 web Patched
CVE-2026-50522webCRITICAL 9.8Patched2026-07-27Joomla Balbooa Forms Unauthenticated Arbitrary File Upload → RCE (CVE-2026-56291) KEV EPSS 15%
CVE-2026-56291 web Unverified
CVE-2026-56291webCRITICAL 9.8Unverified2026-07-27GitLab Notebook-Diff Oj Parser Memory-Corruption Chain → Unauthenticated-Reach RCE (No CVE Yet)
N/A (no CVE assigned as of 2026-07-27 — researcher disclosure via depthfirst.com blog, covered by The Hacker News) web Unverified
N/AwebCRITICALUnverified2026-07-27Crawl4AI JsonCssExtractionStrategy AST Sandbox Escape → Unauthenticated RCE (CVE-2026-53753)
CVE-2026-53753 (GHSA-qxjp-w3pj-48m7) web Patched
CVE-2026-53753webCRITICAL 9.8Patched2026-07-27wp2shell — WordPress Core Pre-Auth SQLi → Row Forgery → Admin Creation → RCE (CVE-2026-63030 + CVE-2026-60137) KEV EPSS 97%
CVE-2026-63030 (REST /batch/v1 route confusion, CVSS 7.5), CVE-2026-60137 (author__not_in SQL injection, CVSS 9.1); GHSA-ff9f-jf42-662q, GHSA-fpp7-x2x2-2mjf web Patched
CVE-2026-63030webCRITICAL 9.1Patched2026-07-19Unauthenticated Arbitrary File Upload RCE in iCagenda for Joomla (CVE-2026-48939) KEV EPSS 20%
CVE-2026-48939 web Patched
CVE-2026-48939webCRITICAL 9.8Patched2026-07-11Sitecore XP Report.ashx Insecure Deserialization RCE (CVE-2021-42237) KEV RW EPSS 98%
CVE-2021-42237 (Sitecore advisory SC2021-003-499266) web Patched
CVE-2021-42237webCRITICAL 9.8Patched2026-07-11XWiki SolrSearch Macro Unauthenticated Groovy RCE (CVE-2025-24893) KEV EPSS 100%
CVE-2025-24893 web Patched
CVE-2025-24893webCRITICAL 9.8Patched2026-07-06XSpeeder SXZOS Pre-Auth eval() Remote Code Execution (CVE-2025-54322) EPSS 15%
CVE-2025-54322 network Unpatched
CVE-2025-54322networkCRITICAL 10Unpatched2026-07-06WP移行専用プラグイン for CPI <= 1.0.2 - Unauthenticated Arbitrary File Upload RCE (CVE-2025-11170)
CVE-2025-11170 web Unpatched
CVE-2025-11170webCRITICAL 9.8Unpatched2026-07-06WordPress WPAMS Plugin Arbitrary File Upload to RCE (CVE-2025-39401)
CVE-2025-39401 web Unverified
CVE-2025-39401webCRITICAL 10Unverified2026-07-06WooCommerce Dynamic Pricing & Discounts (WC Designer Pro) Unauthenticated File Upload RCE (CVE-2025-6440) EPSS 31%
CVE-2025-6440 web Unverified
CVE-2025-6440webCRITICAL 9.8Unverified2026-07-06WavePlayer Unauthenticated Arbitrary File Upload to RCE (CVE-2025-12057)
CVE-2025-12057 web Unverified
CVE-2025-12057webCRITICAL 9.8Unverified2026-07-06ThinkPHP 5.0.24 File Inclusion Leading to Remote Code Execution (CVE-2025-63888)
CVE-2025-63888 web Unverified
CVE-2025-63888webCRITICAL 9.8Unverified2026-07-06Tenda AC9 `AdvSetMacMtuWan` Stack-Based Buffer Overflow (CVE-2025-29384)
CVE-2025-29384 network Unpatched
CVE-2025-29384networkCRITICAL 9.8Unpatched2026-07-06StoreKeeper for WooCommerce Unauthenticated Arbitrary File Upload (CVE-2025-48148) EPSS 15%
CVE-2025-48148 web Unverified
CVE-2025-48148webCRITICAL 9.8Unverified2026-07-06Spring Cloud Gateway Actuator RCE — Vulnerable Environment Lab (CVE-2025-41243)
CVE-2025-41243 web Unpatched
CVE-2025-41243webCRITICAL 10Unpatched2026-07-06Sneeit Framework <= 8.3 Unauthenticated RCE via `call_user_func()` — Rogue Admin Creation (CVE-2025-6389) EPSS 76%
CVE-2025-6389 web Unverified
CVE-2025-6389webCRITICAL 9.8Unverified2026-07-06SmarterMail Auth Bypass via Password Reset to Pre-Auth RCE (CVE-2025-52691 / WT-2026-0001) KEV RW EPSS 86%
CVE-2025-52691 web Patched
CVE-2025-52691webCRITICAL 10Patched2026-07-06SAP NetWeaver Visual Composer Unrestricted File Upload RCE (CVE-2025-31324) KEV RW EPSS 100%
CVE-2025-31324 web Patched
CVE-2025-31324webCRITICAL 10Patched2026-07-06safe-expr-eval: Mitigation Library for the expr-eval Unsafe eval() RCE (CVE-2025-12735)
CVE-2025-12735 misc Patched
CVE-2025-12735miscCRITICAL 9.8Patched2026-07-06Roundcube Webmail Post-Auth RCE via PHP Object Deserialization (CVE-2025-49113) KEV EPSS 99%
CVE-2025-49113 web Patched
CVE-2025-49113webCRITICAL 9.9Patched2026-07-06RediShell: Redis Lua Scripting Use-After-Free Leading to JOP-Chained Remote Code Execution (CVE-2025-49844) EPSS 87%
CVE-2025-49844 binary Patched
CVE-2025-49844binaryCRITICAL 9.9Patched2026-07-06Podlove Podcast Publisher <= 4.2.6 - Unauthenticated Arbitrary File Upload RCE (CVE-2025-10147)
CVE-2025-10147 web Unverified
CVE-2025-10147webCRITICAL 9.8Unverified2026-07-06pgAdmin 4 Restore Feature Regex-Bypass Command Injection RCE (CVE-2025-13780)
CVE-2025-13780 web Unverified
CVE-2025-13780webCRITICAL 9.1Unverified2026-07-06pgAdmin 4 Query Tool Authenticated eval() RCE (CVE-2025-2945) EPSS 54%
CVE-2025-2945 web Patched
CVE-2025-2945webCRITICAL 9.9Patched2026-07-06Oracle Identity Manager `;.wadl` Authentication Bypass + Groovy Script RCE (CVE-2025-61757) KEV EPSS 88%
CVE-2025-61757 web Unpatched
CVE-2025-61757webCRITICAL 9.8Unpatched2026-07-06Monsta FTP Pre-Authentication Remote Code Execution via Arbitrary File Upload (CVE-2025-34299) EPSS 73%
CVE-2025-34299 network Patched
CVE-2025-34299networkCRITICAL 9.8Patched2026-07-06Mongoose `populate()` Match `$where` Bypass Command Injection (CVE-2025-23061)
CVE-2025-23061 web Patched
CVE-2025-23061webCRITICAL 9Patched2026-07-06Laravel Livewire Remote Code Execution via Known APP_KEY (CVE-2025-54068) KEV EPSS 96%
CVE-2025-54068 web Patched
CVE-2025-54068webCRITICAL 9.8Patched2026-07-06Laravel `files.*` Wildcard Validation Bypass via Polyglot JPEG+PHP Upload (CVE-2025-27515)
CVE-2025-27515 web Patched
CVE-2025-27515webCRITICAL 9.8Patched2026-07-06Langflow Pre-Auth RCE Mass Scanner (CVE-2026-27966) EPSS 34%
CVE-2026-27966 (GHSA-3645-fxcv-hqr4) web Patched
CVE-2026-27966webCRITICAL 9.8Patched2026-07-06KiotViet Sync Unauthenticated Arbitrary File Upload (CVE-2025-12674)
CVE-2025-12674 web Unverified
CVE-2025-12674webCRITICAL 9.8Unverified2026-07-06HPE OneView `id-pools/executeCommand` OS Command Injection (CVE-2025-37164) KEV EPSS 90%
CVE-2025-37164 network Unpatched
CVE-2025-37164networkCRITICAL 10Unpatched2026-07-06Hoverfly Middleware Command Injection to RCE (CVE-2025-54123) EPSS 11%
CVE-2025-54123 web Patched
CVE-2025-54123webCRITICAL 9.8Patched2026-07-06Flozen WordPress Theme Unauthenticated Arbitrary File Upload (CVE-2025-49071)
CVE-2025-49071 web Unverified
CVE-2025-49071webCRITICAL 9.8Unverified2026-07-06Flowise CustomMCP Unauthenticated Remote Code Execution via Function() Constructor (CVE-2025-59528) EPSS 87%
CVE-2025-59528 web Patched
CVE-2025-59528webCRITICAL 10Patched2026-07-06DataEase PostgreSQL JDBC Datasource-Validation Bypass to Remote Code Execution (CVE-2025-49002) EPSS 47%
CVE-2025-49002 web Patched
CVE-2025-49002webCRITICAL 9.8Patched2026-07-06camel-coap Header Injection → RCE Self-Contained Reproducer (CVE-2026-33453)
CVE-2026-33453 web Unverified
CVE-2026-33453webCRITICAL 9.8Unverified2026-07-06Apache Parquet-Avro Schema Deserialization RCE/SSRF — Incomplete-Fix Bypass (CVE-2025-30065) EPSS 43%
CVE-2025-30065 misc Patched
CVE-2025-30065miscCRITICAL 9.8Patched2026-07-06Apache Camel `camel-consul` ConsulRegistry Deserialization RCE (CVE-2026-27172)
CVE-2026-27172 web Patched
CVE-2026-27172webCRITICAL 9.8Patched2026-07-06Adobe Experience Manager Forms XXE to JNDI RCE Scanner (CVE-2025-54253) KEV EPSS 88%
CVE-2025-54253 web Unverified
CVE-2025-54253webCRITICAL 10Unverified2026-07-06ZimaOS Arbitrary File Write via Unvalidated File API Path — CVE-2026-28286
CVE-2026-28286 web Unverified
CVE-2026-28286webCRITICALUnverified2026-07-05ZAI-Shell — Unauthenticated Remote Code Execution via P2P Terminal Sharing (CVE-2026-25807)
CVE-2026-25807 network Patched
CVE-2026-25807networkCRITICALPatched2026-07-05XWiki Unauthenticated XAR Import Leading to RCE — CVE-2026-33137
CVE-2026-33137 web Patched
CVE-2026-33137webCRITICAL 9.3Patched2026-07-05WPvivid Backup & Migration Unauthenticated Arbitrary File Upload RCE (CVE-2026-1357) EPSS 33%
CVE-2026-1357 web Unverified
CVE-2026-1357webCRITICALUnverified2026-07-05WordPress Breeze Cache Plugin — Unauthenticated Arbitrary File Upload (CVE-2026-3844) EPSS 28%
CVE-2026-3844 web Unverified
CVE-2026-3844webCRITICALUnverified2026-07-05WordPress "Drag and Drop File Upload for Contact Form 7" Unauthenticated RCE — CVE-2026-5364
CVE-2026-5364 web Unverified
CVE-2026-5364webHIGH 8.1Unverified2026-07-05WooCommerce Wholesale Lead Capture — Unauthenticated Privilege Escalation & File Upload RCE (CVE-2026-27542 / CVE-2026-27540)
CVE-2026-27542 (bundled with CVE-2026-27540) web Unverified
CVE-2026-27542webCRITICAL 9.8Unverified2026-07-05Wing FTP Server Admin Session Poisoning via Lua loadfile() RCE (CVE-2026-44403)
CVE-2026-44403 web Patched
CVE-2026-44403webHIGHPatched2026-07-05Visitor Management System 1.0 — Unrestricted File Upload to RCE (CVE-2026-37748)
CVE-2026-37748 web Unverified
CVE-2026-37748webHIGH 7.2Unverified2026-07-05Veno File Manager Arbitrary PHP File Overwrite (CVE-2026-37068)
CVE-2026-37068 web Unverified
CVE-2026-37068webCRITICALUnverified2026-07-05User Registration Advanced Fields WordPress Plugin Unauthenticated Arbitrary File Upload (CVE-2026-4882)
CVE-2026-4882 web Unverified
CVE-2026-4882webCRITICAL 9.8Unverified2026-07-05UpdraftPlus WordPress Plugin — Unauthenticated RPC Key Bypass to Admin Creation & RCE (CVE-2026-10795)
CVE-2026-10795 web Unverified
CVE-2026-10795webCRITICALUnverified2026-07-05TP-Link DHCP Option 66 Unauthenticated RCE — CVE-2026-11834
CVE-2026-11834 network Unverified
CVE-2026-11834networkCRITICALUnverified2026-07-05Thymeleaf SpEL Injection Remote Code Execution (CVE-2026-41901)
CVE-2026-41901 web Patched
CVE-2026-41901webCRITICALPatched2026-07-05Tenda HG7/HG9/HG10 Router Stack-Based Buffer Overflow — CVE-2026-11499
CVE-2026-11499 network Unverified
CVE-2026-11499networkHIGHUnverified2026-07-05Tasmota fetch_jpg() strcpy() Buffer Overflow in boundary[40] (CVE-2026-38426)
CVE-2026-38426 network Patched
CVE-2026-38426networkCRITICAL 9.8Patched2026-07-05Tasmota fetch_jpg() Integer Wraparound to Heap Corruption (CVE-2026-38427)
CVE-2026-38427 network Patched
CVE-2026-38427networkCRITICAL 9.8Patched2026-07-05Tasmota fetch_jpg() Combined Buffer Overflow RCE Chain (CVE-2026-38422)
CVE-2026-38422 network Patched
CVE-2026-38422networkCRITICAL 9.8Patched2026-07-05Supply Chain Command Injection in AWS CDK's NodejsFunction — CVE-2026-11417
CVE-2026-11417 cloud Patched
CVE-2026-11417cloudHIGH 3.1Patched2026-07-05Spring AI SimpleVectorStore SpEL Injection RCE (CVE-2026-22738)
CVE-2026-22738 web Patched
CVE-2026-22738webCRITICAL 9.8Patched2026-07-05Splunk Secure Gateway jsonpickle Deserialization RCE (CVE-2026-20251) EPSS 32%
CVE-2026-20251 web Unverified
CVE-2026-20251webHIGH 8.8Unverified2026-07-05Spinnaker Clouddriver — Git Clone Shell Injection RCE (CVE-2026-32604)
CVE-2026-32604 (CWE-78) cloud Patched
CVE-2026-32604cloudCRITICAL 10Patched2026-07-05Spectra Gutenberg Blocks Authenticated Remote Code Execution — CVE-2026-7465
CVE-2026-7465 web Unverified
CVE-2026-7465webCRITICAL 8.8Unverified2026-07-05SmarterMail ConnectToHub Unauthenticated SSRF Leading to Remote Command Execution — CVE-2026-24423 KEV RW EPSS 88%
CVE-2026-24423 web Unverified
CVE-2026-24423webCRITICALUnverified2026-07-05SmarterMail Admin Password-Reset Authentication Bypass (CVE-2026-23760) KEV RW EPSS 96%
CVE-2026-23760 web Patched
CVE-2026-23760webCRITICAL 9.3Patched2026-07-05Responsive Filemanager 9.14.0 — Unauthenticated RCE via Duplicate File (CVE-2026-39023)
CVE-2026-39023 web Unpatched
CVE-2026-39023webCRITICALUnpatched2026-07-05Red Hat Cockpit `logsJournal.jsx` Shell Injection RCE (CVE-2026-4802)
CVE-2026-4802 web Unpatched
CVE-2026-4802webHIGHUnpatched2026-07-05rclone RC API Unauthenticated Remote Code Execution (CVE-2026-41179)
CVE-2026-41179 web Patched
CVE-2026-41179webCRITICAL 9.8Patched2026-07-05psf/black GitHub Action RCE via Insecure Regex Version Validation — CVE-2026-31900
CVE-2026-31900 (GHSA-v53h-f6m7-xcgm) misc Patched
CVE-2026-31900miscHIGH 8.7Patched2026-07-05ProFTPD mod_sql Pre-Auth SQL Injection Leading to RCE (CVE-2026-42167)
CVE-2026-42167 network Patched
CVE-2026-42167networkHIGH 8.1Patched2026-07-05Prefect GitRepository Git Argument Injection RCE via `commit_sha` — CVE-2026-5366
CVE-2026-5366 (Huntr bounty e2e88a0f-a8f6-49c9-94c5-e98dc385f07a) web Patched
CVE-2026-5366webHIGHPatched2026-07-05Piotnet Addons for Elementor Pro Unauthenticated Arbitrary File Upload RCE (CVE-2026-4885)
CVE-2026-4885 web Unverified
CVE-2026-4885webCRITICALUnverified2026-07-05Percona PMM Authenticated RCE via PostgreSQL COPY TO PROGRAM (CVE-2026-25212)
CVE-2026-25212 web Patched
CVE-2026-25212webCRITICAL 9.9Patched2026-07-05PbootCMS Authenticated RCE via sitecopyright Field (CVE-2026-36239)
CVE-2026-36239 web Unverified
CVE-2026-36239webCRITICALUnverified2026-07-05OpenXDMoD `user_interface.php` Report Title Command Injection (CVE-2026-45777)
CVE-2026-45777 web Patched
CVE-2026-45777webCRITICALPatched2026-07-05OpenWebUI "Tools" Unsandboxed exec() Remote Code Execution — CVE-2026-0766 EPSS 26%
CVE-2026-0766 (ZDI-26-032, GHSA-cggw-334c-f4mj) web Unverified
CVE-2026-0766webHIGH 8.8Unverified2026-07-05OpenSTAManager Scadenzario Bulk Operations Error-Based SQL Injection — CVE-2026-24418
CVE-2026-24418 web Patched
CVE-2026-24418webHIGH 8.8Patched2026-07-05OpenRemote — Expression Injection RCE in Rules Engine (CVE-2026-39842)
CVE-2026-39842 / GHSA-7mqr-33rv-p3mp web Patched
CVE-2026-39842 / GHSA-7mqr-33rv-p3mpwebCRITICAL 10Patched2026-07-05OpenLearnX Unauthenticated RCE via Container Volume Mount (CVE-2026-41900)
CVE-2026-41900 (GHSA-8h25-q488-4hxw) cloud Patched
CVE-2026-41900cloudHIGH 8.6Patched2026-07-05OpenCode Unauthenticated Local HTTP Server -> Remote Code Execution (CVE-2026-22812) EPSS 17%
CVE-2026-22812 (GHSA-vxw4-wv6m-9hhh) web Patched
CVE-2026-22812webHIGH 8.8Patched2026-07-05OpenClaw Gateway WebSocket Authentication Bypass RCE — CVE-2026-28466
CVE-2026-28466 network Patched
CVE-2026-28466networkCRITICALPatched2026-07-05OpenAM Pre-Authentication RCE via `jato.clientSession` Deserialization (CVE-2026-33439) EPSS 10%
CVE-2026-33439 web Patched
CVE-2026-33439webCRITICAL 9.8Patched2026-07-05OliveTin OS Command Injection via Shell Mode Arguments (CVE-2026-27626)
CVE-2026-27626 / GHSA-49gm-hh7w-wfvf web Unverified
CVE-2026-27626 / GHSA-49gm-hh7w-wfvfwebCRITICAL 9.9Unverified2026-07-05NVIDIA Triton Inference Server SageMaker Auth Bypass to Unauthenticated RCE (CVE-2026-24207)
CVE-2026-24207 (sibling: CVE-2026-24206, Vertex AI, analysis only) network Patched
CVE-2026-24207networkCRITICAL 9.8Patched2026-07-05Node.js protobufjs Dynamic Type Compilation RCE (CVE-2026-41242)
CVE-2026-41242 web Patched
CVE-2026-41242webCRITICALPatched2026-07-05nginx PoolSlip × Rift Chained ASLR-Independent Remote Code Execution (CVE-2026-9256 / CVE-2026-42945)
CVE-2026-9256 ("PoolSlip"), chained with CVE-2026-42945 ("rift") web Unverified
CVE-2026-9256webCRITICALUnverified2026-07-05n8n Unauthenticated Arbitrary File Read to RCE Full Chain — CVE-2026-21858 + CVE-2025-68613 EPSS 78%
CVE-2026-21858, CVE-2025-68613 web Patched
CVE-2026-21858, CVE-2025-68613webCRITICAL 10Patched2026-07-05n8n HTTP Request Node Pagination Prototype Pollution → Remote Code Execution (CVE-2026-44789)
CVE-2026-44789 / GHSA-c8xv-5998-g76h web Patched
CVE-2026-44789 / GHSA-c8xv-5998-g76hwebCRITICAL 9.4Patched2026-07-05MR9600 Router Bluetooth/JNAP Management Interface RCE Injection (CVE-2026-6992)
CVE-2026-6992 network Unverified
CVE-2026-6992networkHIGHUnverified2026-07-05MLflow / MLServer Insecure Pickle Deserialization RCE — CVE-2026-0596
CVE-2026-0596 (GHSA-rvhj-8chj-8v3c) web Unverified
CVE-2026-0596webCRITICAL 9.6Unverified2026-07-05MindsDB — Handler Path Traversal to Remote Code Execution (CVE-2026-27483) EPSS 11%
CVE-2026-27483 web Patched
CVE-2026-27483webCRITICALPatched2026-07-05Microsoft Semantic Kernel In-Memory Vector Store Filter eval() Sandbox Bypass RCE (CVE-2026-26030)
CVE-2026-26030 misc Patched
CVE-2026-26030miscCRITICALPatched2026-07-05Mercator Configuration SSRF Chained to Internal Redis RCE (CVE-2026-49345)
CVE-2026-49345 web Unverified
CVE-2026-49345webCRITICALUnverified2026-07-05MCPJam Inspector Unauthenticated Command Injection RCE (CVE-2026-23744) EPSS 45%
CVE-2026-23744 web Patched
CVE-2026-23744webCRITICALPatched2026-07-05MCPJam Inspector / Arcane MCP Connect Command Injection RCE via Host-Header Vhost Routing (CVE-2026-23520)
CVE-2026-23520 web Patched
CVE-2026-23520webCRITICALPatched2026-07-05Math.js Expression Parser Sandbox Bypass RCE (CVE-2026-40897)
CVE-2026-40897 web Patched
CVE-2026-40897webCRITICALPatched2026-07-05lwIP SNMPv3 USM Stack-Based Buffer Overflow (CVE-2026-8836)
CVE-2026-8836 network Patched
CVE-2026-8836networkCRITICAL 9.8Patched2026-07-05LiteLLM /config/update Broken Access Control (CVE-2026-35029) EPSS 26%
CVE-2026-35029 web Patched
CVE-2026-35029webHIGH 8.8Patched2026-07-05Langflow Unauthenticated Remote Code Execution via `validate/code` Endpoint (CVE-2026-0770) KEV EPSS 63%
CVE-2026-0770 web Patched
CVE-2026-0770webCRITICALPatched2026-07-05Langflow Remote Code Execution — CVE-2026-27966 EPSS 34%
CVE-2026-27966 web Patched
CVE-2026-27966webCRITICAL 9.8Patched2026-07-05Langflow Custom Component Remote Code Execution — CVE-2026-33017 KEV EPSS 96%
CVE-2026-33017 web Patched
CVE-2026-33017webCRITICALPatched2026-07-05Krayin CRM — TinyMCE Upload Unrestricted File Upload to RCE (CVE-2026-38526)
CVE-2026-38526 web Unverified
CVE-2026-38526webCRITICALUnverified2026-07-05KnowledgeDeliver ASP.NET ViewState Deserialization RCE via Hardcoded Machine Keys — CVE-2026-5426
CVE-2026-5426 web Unverified
CVE-2026-5426webCRITICALUnverified2026-07-05Kanboard — Missing Access Control on Plugin Installation Leads to Administrative RCE via Webshell Plugin (CVE-2026-25924)
CVE-2026-25924 / GHSA-grch-p7vf-vc4f web Patched
CVE-2026-25924 / GHSA-grch-p7vf-vc4fwebHIGH 8.4Patched2026-07-05Jinjava Server-Side Template Injection to RCE via Jackson ObjectMapper (CVE-2026-25526)
CVE-2026-25526 web Patched
CVE-2026-25526webCRITICALPatched2026-07-05Hustle (WordPress Popup) Authenticated Arbitrary File Upload via Module Import (CVE-2026-0911)
CVE-2026-0911 web Unverified
CVE-2026-0911webHIGHUnverified2026-07-05Handlebars AST Injection Remote Code Execution — CVE-2026-33937
CVE-2026-33937 web Patched
CVE-2026-33937webCRITICALPatched2026-07-05Group-Office TNEF Attachment Handler OS Command Injection (CVE-2026-25512) EPSS 19%
CVE-2026-25512 web Patched
CVE-2026-25512webCRITICAL 9.4Patched2026-07-05Group-Office PHP Deserialization Remote Code Execution (CVE-2026-34838)
CVE-2026-34838 (GHSA-h22j-frrf-5vxq) web Patched
CVE-2026-34838webCRITICALPatched2026-07-05Gotenberg 8.29.1 Unauthenticated ExifTool Metadata Key Injection RCE (CVE-2026-42589)
CVE-2026-42589 web Patched
CVE-2026-42589webCRITICAL 9.8Patched2026-07-05Gogs Organization-Name Path Traversal to RCE via Git Hooks — CVE-2026-52813
CVE-2026-52813 web Patched
CVE-2026-52813webINFOPatched2026-07-05Ghost CMS Theme JSONPath Remote Code Execution — CVE-2026-29053
CVE-2026-29053 (GHSA-cgc2-rcrh-qr5x) web Patched
CVE-2026-29053webHIGHPatched2026-07-05FUXA SCADA/HMI — Unauthenticated Path Traversal to Remote Code Execution (CVE-2026-25895) EPSS 11%
CVE-2026-25895 web Patched
CVE-2026-25895webCRITICAL 9.8Patched2026-07-05FreeScout Zero-Click RCE via Email Attachment Filename Sanitization Bypass ("Mail2Shell") — CVE-2026-28289 EPSS 31%
CVE-2026-28289 web Patched
CVE-2026-28289webCRITICAL 10Patched2026-07-05Fortinet FortiSandbox "Start VNC" OS Command Injection (CVE-2026-25089) KEV EPSS 76%
CVE-2026-25089 network Patched
CVE-2026-25089networkCRITICAL 9.8Patched2026-07-05Everest Forms Unauthenticated PHP Object Injection to RCE (CVE-2026-3296)
CVE-2026-3296 web Patched
CVE-2026-3296webCRITICAL 9.8Patched2026-07-05Everest Forms Pro Unauthenticated PHP Code Injection via Calculation Addon (CVE-2026-3300) EPSS 39%
CVE-2026-3300 web Unverified
CVE-2026-3300webCRITICALUnverified2026-07-05EspoCRM Authenticated RCE via Formula ACL Bypass + Attachment Path Traversal — CVE-2026-33656
CVE-2026-33656 web Patched
CVE-2026-33656webCRITICALPatched2026-07-05Dolibarr ERP/CRM OS Command Injection via MAIN_ODT_AS_PDF (CVE-2026-23500)
CVE-2026-23500 / GHSA-w5j3-8fcr-h87w web Patched
CVE-2026-23500 / GHSA-w5j3-8fcr-h87wwebCRITICALPatched2026-07-05docling-core Unsafe YAML Deserialization Leading to Code Execution — CVE-2026-24009
CVE-2026-24009 misc Patched
CVE-2026-24009miscHIGHPatched2026-07-05Discuz! X5.0 Race Condition + CAPTCHA-Solving Pre-Auth to RCE Chain (CVE-2026-49952)
CVE-2026-49952 (chain also referenced as KIS-2026-09, KIS-2026-10, KIS-2026-11) web Unverified
CVE-2026-49952webCRITICALUnverified2026-07-05dedoc/scramble Laravel API-Doc Generator Unauthenticated eval() RCE (CVE-2026-44262)
CVE-2026-44262 / [GHSA-4rm2-28vj-fj39](https://github.com/advisories/GHSA-4rm2-28vj-fj39) web Patched
CVE-2026-44262 / [GHSA-4rm2-28vj-fj39]webCRITICALPatched2026-07-05DbGate Unauthenticated RCE via JSON Script Runner (CVE-2026-47668)
CVE-2026-47668 web Patched
CVE-2026-47668webCRITICAL 3.1Patched2026-07-05DbGate `loadReader` `functionName` Injection RCE (CVE-2026-48017)
CVE-2026-48017 / GHSA-hv83-ggc4-v385 web Patched
CVE-2026-48017 / GHSA-hv83-ggc4-v385webHIGH 8.8Patched2026-07-05Coolify Authenticated Remote Command Injection via Deployment Config (CVE-2026-34038)
CVE-2026-34038 (GHSA-qqrq-r9h4-x6wp) web Patched
CVE-2026-34038webCRITICAL 10Patched2026-07-05Contact Form by Supsystic <= 1.7.36 Unauthenticated SSTI to RCE (CVE-2026-4257) EPSS 41%
CVE-2026-4257 web Unverified
CVE-2026-4257webCRITICALUnverified2026-07-05Chamilo LMS Authenticated RCE via Unrestricted File Upload — CVE-2026-29041
CVE-2026-29041 web Patched
CVE-2026-29041webHIGH 8.8Patched2026-07-05Centreon Multi-Vector RCE — Path Traversal, Command Injection & Blind SQLi (CVE-2026-2749)
CVE-2026-2749 (bundled with related CVE-2026-2750, CVE-2026-2751) web Patched
CVE-2026-2749webCRITICALPatched2026-07-05Casdoor Authenticated Path Traversal to Arbitrary File Write (CVE-2026-6815)
CVE-2026-6815 web Unverified
CVE-2026-6815webHIGHUnverified2026-07-05Cacti Authenticated OS Command Injection via Host Notes Variable (CVE-2026-39949)
CVE-2026-39949 web Patched
CVE-2026-39949webHIGHPatched2026-07-05Budibase Authentication Bypass to Plugin-Upload Reverse Shell — CVE-2026-31816 EPSS 15%
CVE-2026-31816 web Unverified
CVE-2026-31816webCRITICALUnverified2026-07-05BookingPress Pro Unauthenticated Arbitrary File Upload via Data URI Signature Field (CVE-2026-6960)
CVE-2026-6960 web Unverified
CVE-2026-6960webCRITICAL 9.8Unverified2026-07-05BoidCMS — Authenticated File Upload to RCE via Template Injection (CVE-2026-39387)
CVE-2026-39387 web Patched
CVE-2026-39387webHIGHPatched2026-07-05Bludit CMS API Unrestricted File Upload to RCE (CVE-2026-25099)
CVE-2026-25099 web Patched
CVE-2026-25099webHIGHPatched2026-07-05BetterDocs Pro Unauthenticated Local File Inclusion to RCE — CVE-2026-7515
CVE-2026-7515 web Unverified
CVE-2026-7515webCRITICAL 9.8Unverified2026-07-05Avada Builder Unauthenticated RCE via call_user_func() Allowlist Bypass (CVE-2026-6279)
CVE-2026-6279 web Unverified
CVE-2026-6279webCRITICALUnverified2026-07-05ASUSTOR ADM vpnupload.cgi Format String / Stack Buffer Overflow RCE — CVE-2026-6643
CVE-2026-6643 binary Unverified
CVE-2026-6643binaryCRITICALUnverified2026-07-05Apache Tomcat Tribes EncryptInterceptor Fail-Open Unauthenticated RCE (CVE-2026-34486) KEV EPSS 99%
CVE-2026-34486 web Patched
CVE-2026-34486webCRITICALPatched2026-07-05Apache Solr Velocity Template Injection RCE (CVE-2026-44825)
CVE-2026-44825 web Patched
CVE-2026-44825webCRITICAL 9.8Patched2026-07-05Apache Solr UNC Path Validation Bypass to RCE (CVE-2026-22444)
CVE-2026-22444 web Patched
CVE-2026-22444webCRITICALPatched2026-07-05Apache NiFi 2.8.0 — EXECUTE_CODE Permission Bypass to Groovy RCE (CVE-2026-39816)
CVE-2026-39816 web Patched
CVE-2026-39816webCRITICALPatched2026-07-05Apache MINA acceptMatchers Deserialization Filter Bypass to RCE (CVE-2026-42779)
CVE-2026-42779 network Patched
CVE-2026-42779networkCRITICAL 9.8Patched2026-07-05Apache Camel camel-coap Header Injection to Remote Code Execution (CVE-2026-33453)
CVE-2026-33453 web Patched
CVE-2026-33453webCRITICAL 10Patched2026-07-05Apache ActiveMQ Jolokia addNetworkConnector Spring Bean RCE (CVE-2026-42588)
CVE-2026-42588 web Patched
CVE-2026-42588webHIGH 8.1Patched2026-07-05Apache ActiveMQ Classic Jolokia addNetworkConnector Xbean Spring-XML RCE (CVE-2026-34197) KEV EPSS 97%
CVE-2026-34197 (related bypass: CVE-2026-42588) network Patched
CVE-2026-34197networkCRITICALPatched2026-07-05AdonisJS bodyparser Path Traversal to Arbitrary File Write (CVE-2026-21440)
CVE-2026-21440 (GHSA-gvq6-hvvp-h34h) web Patched
CVE-2026-21440webCRITICAL 9.2Patched2026-07-05Redis Vector Set Duplicate HNSW Node ID RCE
None assigned as of 2026-07-03 network Unverified
None assigned as of 2026-07-03networkCRITICALUnverified2026-07-03PHP 8.5.7 StreamBucket-to-SOAP Numeric Cookie Remote Code Execution
None assigned as of 2026-07-03 web Unverified
None assigned as of 2026-07-03webCRITICALUnverified2026-07-03Lunar Client Modrinth Explore Raw-HTML to Local Launcher Execution Chain
None assigned as of 2026-07-03 binary Unverified
None assigned as of 2026-07-03binaryCRITICAL 3.1Unverified2026-07-03libssh2 Unchecked SSH packet_length Integer Wrap to RCE (CVE-2026-55200)
CVE-2026-55200 network Patched
CVE-2026-55200networkCRITICALPatched2026-07-03libssh2 Publickey Subsystem List Parser Heap Corruption to Code Execution
None assigned as of 2026-07-03 network Unverified
None assigned as of 2026-07-03networkCRITICALUnverified2026-07-03Langflow Missing-Authentication Remote Code Execution (CVE-2025-3248) KEV RW EPSS 100%
CVE-2025-3248 web Patched
CVE-2025-3248webCRITICAL 9.8Patched2026-07-03Ladybird Browser WebAssembly ESM Host-Function Use-After-Free RCE
None assigned as of 2026-07-03 web Unverified
None assigned as of 2026-07-03webCRITICALUnverified2026-07-03Gogs Admin User Edit CSRF to Git Hook RCE
None assigned as of 2026-07-03 web Unverified
None assigned as of 2026-07-03webCRITICALUnverified2026-07-03Flowise Custom MCP Environment Variable Case Bypass
None assigned as of 2026-07-03 web Unverified
None assigned as of 2026-07-03webHIGHUnverified2026-07-03Floci API Gateway VTL RCE + IAM Scope Bypass
None assigned as of 2026-07-03 cloud Unverified
None assigned as of 2026-07-03cloudCRITICALUnverified2026-07-03Unauthenticated RCE in Mirasvit Full Page Cache Warmer for Magento 2 (CVE-2026-45247) KEV EPSS 28%
CVE-2026-45247 web Unverified
CVE-2026-45247webCRITICAL 9.3Unverified2026-07-01Unauthenticated RCE in Joomla Content Editor (JCE) Profile Import (CVE-2026-48907) KEV EPSS 78%
CVE-2026-48907 web Patched
CVE-2026-48907webCRITICAL 10Patched2026-07-01Cisco Unified CM WebDialer SSRF to Arbitrary File Write / RCE (CVE-2026-20230) KEV EPSS 88%
CVE-2026-20230 network Unverified
CVE-2026-20230networkCRITICAL 8.6Unverified2026-07-01SP Page Builder (Joomla) Unauthenticated File Upload RCE (CVE-2026-48908) KEV EPSS 15%
CVE-2026-48908 (GHSA-8fwr-8fxr-8v2p) web Patched
CVE-2026-48908webCRITICAL 10Patched2026-06-30libssh2 SSH Packet Length OOB Heap Write / Unauthenticated RCE (CVE-2026-55200)
CVE-2026-55200 network Patched
CVE-2026-55200networkCRITICAL 9.8Patched2026-06-30GNU Inetutils telnetd Unauthenticated Root RCE via NEW-ENVIRON (CVE-2026-24061) KEV EPSS 98%
CVE-2026-24061 network Patched
CVE-2026-24061networkCRITICAL 9.8Patched2026-06-30GeoVision GV-I/O Box 4E DVRSearch Unauthenticated Stack Buffer Overflow RCE (CVE-2026-12485)
CVE-2026-12485 network Patched
CVE-2026-12485networkCRITICAL 10Patched2026-06-30FFmpeg MagicYUV Decoder Out-of-Bounds Write / RCE — PixelSmash (CVE-2026-8461)
CVE-2026-8461 binary Patched
CVE-2026-8461binaryHIGH 8.8Patched2026-06-30Splunk Enterprise Pre-Auth RCE via PostgreSQL Sidecar (CVE-2026-20253) KEV EPSS 97%
CVE-2026-20253 web Patched
CVE-2026-20253webCRITICALPatched2026-06-28Ivanti Sentry Pre-Auth RCE + Auth Bypass (CVE-2026-10520 / CVE-2026-10523) KEV EPSS 100%
CVE-2026-10520, CVE-2026-10523 network Patched
CVE-2026-10520, CVE-2026-10523networkCRITICAL 10Patched2026-06-28TossUp — TerraMaster TOS Unauthenticated Redis Root RCE + NFS LPE
N/A (vendor confirmed TOS4 is EOL; no fix planned) network Unpatched
N/AnetworkCRITICALUnpatched2026-05-18Windows MMC MSC EvilTwin - CVE-2025-26633 KEV RW EPSS 30%
CVE-2025-26633 binary Unverified
CVE-2025-26633binaryHIGHUnverified2026-05-17ToolShell - SharePoint Unauthenticated RCE Chain KEV RW EPSS 100%
CVE-2025-53770, CVE-2025-53771, CVE-2025-49704, CVE-2025-49706 web Patched
CVE-2025-53770, CVE-2025-53771, CVE-2025-49704, CVE-2025-49706webCRITICALPatched2026-05-17React2Shell - Next.js RSC Unauthenticated RCE KEV RW EPSS 100%
CVE-2025-55182 web Patched
CVE-2025-55182webCRITICAL 10Patched2026-05-17Palo Alto PAN-OS GlobalProtect Unauthenticated RCE (CVE-2024-3400) KEV RW EPSS 100%
CVE-2024-3400 web Patched
CVE-2024-3400webCRITICAL 10Patched2026-05-17Jenkins CLI Arbitrary File Read to RCE (CVE-2024-23897) KEV RW EPSS 100%
CVE-2024-23897 web Patched
CVE-2024-23897webCRITICAL 9.8Patched2026-05-17Ivanti Connect Secure Pre-Auth RCE (Stack Overflow) KEV RW EPSS 100%
CVE-2025-0282 network Unverified
CVE-2025-0282networkCRITICAL 9Unverified2026-05-17IngressNightmare - Kubernetes Ingress-NGINX Unauthenticated RCE EPSS 100%
CVE-2025-1974 (primary); also CVE-2025-1097, CVE-2025-1098, CVE-2025-24514 cloud Unverified
CVE-2025-1974cloudCRITICAL 9.8Unverified2026-05-17Fortinet FortiManager FortiJump Unauthenticated RCE (CVE-2024-47575) KEV EPSS 95%
CVE-2024-47575 network Unverified
CVE-2024-47575networkCRITICAL 9.8Unverified2026-05-17Erlang/OTP SSH Pre-Auth RCE - CVE-2025-32433 KEV EPSS 99%
CVE-2025-32433 network Patched
CVE-2025-32433networkCRITICAL 10Patched2026-05-17Confluence SSTI RCE - CVE-2023-22527 KEV RW EPSS 100%
CVE-2023-22527 web Patched
CVE-2023-22527webCRITICAL 10Patched2026-05-17Confluence Post-Auth RCE - CVE-2024-21683 EPSS 88%
CVE-2024-21683 web Unverified
CVE-2024-21683webHIGH 8.3Unverified2026-05-17Apache httpd mod_http2 Double-Free Pre-Auth RCE - CVE-2026-23918 EPSS 50%
CVE-2026-23918 web Patched
CVE-2026-23918webCRITICALPatched2026-05-17Windows OLE Zero-Click RCE via Outlook RTF (CVE-2025-21298) EPSS 81%
CVE-2025-21298 binary Patched
CVE-2025-21298binaryCRITICAL 9.8Patched2026-05-16VMware vCenter Server DCE/RPC Heap Overflow RCE (CVE-2024-37079) KEV EPSS 22%
CVE-2024-37079 network Patched
CVE-2024-37079networkCRITICAL 9.8Patched2026-05-16OpenSSH regreSSHion Signal-Handler Race Unauthenticated RCE (CVE-2024-6387) EPSS 100%
CVE-2024-6387 network Patched
CVE-2024-6387networkHIGH 8.1Patched2026-05-16Fortinet FortiOS SSL VPN Unauthenticated RCE (CVE-2024-21762) KEV RW EPSS 84%
CVE-2024-21762 web Patched
CVE-2024-21762webCRITICAL 9.6Patched2026-05-16Apache Parquet Java Unsafe Deserialization RCE (CVE-2025-30065) EPSS 43%
CVE-2025-30065 misc Patched
CVE-2025-30065miscCRITICAL 10Patched2026-05-16Adobe Acrobat/Reader Prototype Pollution Sandbox Escape (CVE-2026-34621) KEV
CVE-2026-34621 binary Unverified
CVE-2026-34621binaryCRITICAL 9.8Unverified2026-05-16HTTP Protocol Stack Remote Code Execution Vulnerability (CVE-2021-31166) KEV EPSS 100%
CVE-2021-31166 network Patched
CVE-2021-31166networkCRITICAL 9.8Patched2026-05-15NGINX Rift — Heap Buffer Overflow RCE (CVE-2026-42945) EPSS 68%
CVE-2026-42945 web Unverified
CVE-2026-42945webCRITICAL 9.8Unverified2026-05-14