PoC Archive PoC Archive

tag

Unauthenticated-Rce

Wing FTP Server NULL-Byte Lua Injection Unauthenticated RCE (CVE-2025-47812) KEV EPSS 93%
CVE-2025-47812 web Patched
CVE-2025-47812webCRITICAL 10Patched2026-07-06Samsung MagicINFO 9 Server Unauthenticated Path Traversal to RCE (CVE-2025-4632) KEV EPSS 24%
CVE-2025-4632 web Patched
CVE-2025-4632webCRITICAL 9.8Patched2026-07-06React Server Components Flight-Protocol Prototype Pollution RCE — "React2Shell" (CVE-2025-55182) KEV RW EPSS 100%
CVE-2025-55182 web Patched
CVE-2025-55182webCRITICAL 10Patched2026-07-06Invision Community Theme Editor Template Injection Unauthenticated RCE (CVE-2025-47916) EPSS 84%
CVE-2025-47916 web Patched
CVE-2025-47916webCRITICAL 10Patched2026-07-06Cisco AsyncOS Spam Quarantine (TCP/6025) Exposure & IOC Scanner (CVE-2025-20393) KEV EPSS 30%
CVE-2025-20393 network Unverified
CVE-2025-20393networkCRITICAL 10Unverified2026-07-06ACF Extended (ACFE) `prepare_form()` Unauthenticated RCE via Privilege Escalation (CVE-2025-13486) EPSS 68%
CVE-2025-13486 web Unverified
CVE-2025-13486webCRITICAL 9.8Unverified2026-07-06WebStack WordPress Theme Unauthenticated Arbitrary File Upload RCE — CVE-2026-1555
CVE-2026-1555 web Unverified
CVE-2026-1555webCRITICAL 9.8Unverified2026-07-05SP LMS PHP Object Injection → Unauthenticated RCE (CVE-2026-48909)
CVE-2026-48909 (GHSA-gf8c-xmwj-whrh) web Patched
CVE-2026-48909webCRITICAL 9.5Patched2026-07-05FortiAuthenticator Unauthenticated RCE Endpoint Probe (CVE-2026-44277)
CVE-2026-44277 web Patched
CVE-2026-44277webCRITICALPatched2026-07-05Cockpit Unauthenticated Remote Code Execution via SSH Argument Injection (CVE-2026-4631) EPSS 15%
CVE-2026-4631 (GHSA-m4gv-x78h-3427) web Patched
CVE-2026-4631webCRITICAL 9.8Patched2026-07-05