PoC Archive PoC Archive

tag

Soap

  • CVE-2026-16232 network CRITICAL 9.1 KEV EPSS 71%

    Check Point Security Management / Multi-Domain Server SmartConsole Authentication Bypass via Forged Application Certificate Bind (CVE-2026-16232)

    CVE-2026-16232 is an unauthenticated authentication bypass (CWE-287) in the Check Point SmartConsole login path on Security Management and Multi-Domain Management servers. During the legacy SIC/CPMI bootstrap the management server volunteers its own SIC…

    Patched 2026-08-09
  • CVE-2025-60854 network CRITICAL 9.8

    D-Link AX1500 SetDeviceSettings `DeviceName` OS Command Injection (CVE-2025-60854)

    The D-Link AX1500 web management interface exposes a SetDeviceSettings SOAP action (reached via the /DHMAPI/ HNAP-style endpoint) that lets a client update the router's DeviceName. The vulnerable firmware function (identified in the binary as…

    Patched 2026-07-06
  • CVE-2026-45504 web HIGH

    Microsoft Exchange Authenticated Arbitrary File Read via EWS Reference Attachment (CVE-2026-45504)

    CVE-2026-45504 is an authenticated arbitrary file read vulnerability in Microsoft Exchange Server. An attacker with valid mailbox credentials authenticates to OWA and, via the Exchange Web Services (EWS) CreateItem/CreateAttachment SOAP calls, creates a…

    Patched 2026-07-05
  • CVE-2026-30849 web HIGH

    MantisBT SOAP `mc_issue_add` Authentication Bypass (Type Juggling) — CVE-2026-30849

    MantisBT's legacy SOAP API is affected by a PHP loose-comparison ("type juggling") flaw in password verification reachable via the mcissueadd SOAP operation, allowing an attacker to authenticate without knowing a valid password by supplying a specially…

    Patched 2026-07-05
  • None assigned as of 2026-07-03 web CRITICAL

    PHP 8.5.7 StreamBucket-to-SOAP Numeric Cookie Remote Code Execution

    This PoC demonstrates a full memory-corruption-to-RCE chain in PHP 8.5.7 built from three engine/extension behaviors chained together: ArrayIterator can mutate normally-protected internal object properties (bypassing typed-property/visibility/readonly…

    Unverified 2026-07-03