PoC Archive PoC Archive

tag

Remote

Nginx HTTP/3 QUIC Pool Corruption RCE (CVE-2026-42530)
CVE-2026-42530 binary Unverified
CVE-2026-42530binaryHIGH 8.1Unverified2026-09-03wp2shell — WordPress Core Pre-Auth SQLi → Row Forgery → Admin Creation → RCE (CVE-2026-63030 + CVE-2026-60137) KEV EPSS 97%
CVE-2026-63030 (REST /batch/v1 route confusion, CVSS 7.5), CVE-2026-60137 (author__not_in SQL injection, CVSS 9.1); GHSA-ff9f-jf42-662q, GHSA-fpp7-x2x2-2mjf web Patched
CVE-2026-63030webCRITICAL 9.1Patched2026-07-19SimpleHelp OIDC Authentication Bypass via Unverified JWT Signature (CVE-2026-48558) KEV EPSS 12%
CVE-2026-48558 web Patched
CVE-2026-48558webCRITICAL 10Patched2026-07-19Langflow Responses API IDOR — Execute Another User's Flow (CVE-2026-55255) KEV
CVE-2026-55255 (GHSA-qrpv-q767-xqq2) web Patched
CVE-2026-55255webHIGH 8.4Patched2026-07-19Cisco Unified Communications Manager WebDialer SSRF → Arbitrary File Write → Root (CVE-2026-20230) KEV EPSS 88%
CVE-2026-20230 (cisco-sa-cucm-ssrf-cXPnHcW) network Patched
CVE-2026-20230networkCRITICAL 8.6Patched2026-07-19Adobe ColdFusion RDS Path Traversal → Arbitrary File Read/Write → RCE (CVE-2026-48282) KEV EPSS 42%
CVE-2026-48282 (Adobe APSB26-68) web Patched
CVE-2026-48282webCRITICAL 10Patched2026-07-19SonicWall SMA1000 WorkPlace SSRF → Internal Erlang RPC Remote Code Execution (CVE-2026-15409) KEV RW EPSS 84%
CVE-2026-15409 (SNWLID-2026-0008) network Patched
CVE-2026-15409networkCRITICAL 10Patched2026-07-15Flowise Enterprise Authentication Bypass via Hardcoded Default JWT Secrets (CVE-2026-56271)
CVE-2026-56271 (GHSA-cc4f-hjpj-g9p8) web Patched
CVE-2026-56271webCRITICAL 9.8Patched2026-07-12Crawl4AI Docker API Server Arbitrary File Write via `output_path` (CVE-2026-56260)
CVE-2026-56260 (GHSA-365w-hqf6-vxfg) web Patched
CVE-2026-56260webCRITICAL 9.1Patched2026-07-12ZKTeco BioTime v8.5.5 Unauthenticated Path Traversal / Arbitrary File Read via iclock API (CVE-2023-38950) KEV EPSS 85%
CVE-2023-38950 web Patched
CVE-2023-38950webHIGH 7.5Patched2026-07-11Unauthenticated Arbitrary File Upload RCE in iCagenda for Joomla (CVE-2026-48939) KEV EPSS 20%
CVE-2026-48939 web Patched
CVE-2026-48939webCRITICAL 9.8Patched2026-07-11Sitecore XP Report.ashx Insecure Deserialization RCE (CVE-2021-42237) KEV RW EPSS 98%
CVE-2021-42237 (Sitecore advisory SC2021-003-499266) web Patched
CVE-2021-42237webCRITICAL 9.8Patched2026-07-11LiteLLM Proxy Pre-Authentication SQL Injection via Error-Handling Callback (CVE-2026-42208) KEV EPSS 89%
CVE-2026-42208 (GHSA-r75f-5x8p-qvmc) web Patched
CVE-2026-42208webCRITICAL 9.8Patched2026-07-11Gitea Docker Image Reverse-Proxy Authentication Bypass — "One Header, Any User" (CVE-2026-20896)
CVE-2026-20896 (GHSA-f75j-4cw6-rmx4) web Patched
CVE-2026-20896webCRITICAL 9.8Patched2026-07-11D-Link DIR-820L `get_set.ccp` LAN Configuration OS Command Injection (CVE-2022-26258) KEV EPSS 80%
CVE-2022-26258 network Unverified
CVE-2022-26258networkCRITICAL 9.8Unverified2026-07-11XRING — XQUIC QPACK Ring Buffer Resize Underflow (Remote Unauthenticated DoS)
network Unpatched
—networkCRITICALUnpatched2026-07-08