PoC Archive PoC Archive

tag

Soap

Check Point Security Management / Multi-Domain Server SmartConsole Authentication Bypass via Forged Application Certificate Bind (CVE-2026-16232) KEV EPSS 72%
CVE-2026-16232 network Patched
CVE-2026-16232networkCRITICAL 9.1Patched2026-08-09D-Link AX1500 SetDeviceSettings `DeviceName` OS Command Injection (CVE-2025-60854)
CVE-2025-60854 network Patched
CVE-2025-60854networkCRITICAL 9.8Patched2026-07-06Microsoft Exchange Authenticated Arbitrary File Read via EWS Reference Attachment (CVE-2026-45504)
CVE-2026-45504 web Patched
CVE-2026-45504webHIGHPatched2026-07-05MantisBT SOAP `mc_issue_add` Authentication Bypass (Type Juggling) — CVE-2026-30849
CVE-2026-30849 web Patched
CVE-2026-30849webHIGHPatched2026-07-05PHP 8.5.7 StreamBucket-to-SOAP Numeric Cookie Remote Code Execution
None assigned as of 2026-07-03 web Unverified
None assigned as of 2026-07-03webCRITICALUnverified2026-07-03