PoC Archive PoC Archive

tag

Webshell

WP Cookie Notice Unauthenticated File Upload RCE (CVE-2026-82970)
CVE-2026-82970 web Unverified
CVE-2026-82970webCRITICAL 10Unverified2026-09-03Citrix NetScaler ADC/Gateway -- Pre-Auth SAML PrefixList Heap Overflow to RCE (CVE-2026-8452) KEV
CVE-2026-8452 network Patched
CVE-2026-8452networkCRITICAL 9.8Patched2026-08-16Joomla Balbooa Forms Unauthenticated Arbitrary File Upload → RCE (CVE-2026-56291) KEV EPSS 15%
CVE-2026-56291 web Unverified
CVE-2026-56291webCRITICAL 9.8Unverified2026-07-27Adobe ColdFusion RDS Path Traversal → Arbitrary File Read/Write → RCE (CVE-2026-48282) KEV EPSS 42%
CVE-2026-48282 (Adobe APSB26-68) web Patched
CVE-2026-48282webCRITICAL 10Patched2026-07-19WordPress WPAMS Plugin Arbitrary File Upload to RCE (CVE-2025-39401)
CVE-2025-39401 web Unverified
CVE-2025-39401webCRITICAL 10Unverified2026-07-06Webkul Medical Prescription Attachment for WooCommerce — Unrestricted File Upload to Web Shell (CVE-2025-29009)
CVE-2025-29009 web Patched
CVE-2025-29009webCRITICAL 10Patched2026-07-06WavePlayer Unauthenticated Arbitrary File Upload to RCE (CVE-2025-12057)
CVE-2025-12057 web Unverified
CVE-2025-12057webCRITICAL 9.8Unverified2026-07-06ThinkPHP 5.0.24 File Inclusion Leading to Remote Code Execution (CVE-2025-63888)
CVE-2025-63888 web Unverified
CVE-2025-63888webCRITICAL 9.8Unverified2026-07-06StoreKeeper for WooCommerce Unauthenticated Arbitrary File Upload (CVE-2025-48148) EPSS 15%
CVE-2025-48148 web Unverified
CVE-2025-48148webCRITICAL 9.8Unverified2026-07-06KiotViet Sync Unauthenticated Arbitrary File Upload (CVE-2025-12674)
CVE-2025-12674 web Unverified
CVE-2025-12674webCRITICAL 9.8Unverified2026-07-06Flozen WordPress Theme Unauthenticated Arbitrary File Upload (CVE-2025-49071)
CVE-2025-49071 web Unverified
CVE-2025-49071webCRITICAL 9.8Unverified2026-07-06Cibeles AI `actualizador_git.php` Unauthenticated Arbitrary File Upload / RCE (CVE-2025-13595)
CVE-2025-13595 web Unverified
CVE-2025-13595webCRITICAL 9.8Unverified2026-07-06AI Feeds `actualizador_git.php` Unauthenticated Arbitrary File Upload / RCE (CVE-2025-13597)
CVE-2025-13597 web Unverified
CVE-2025-13597webCRITICAL 9.8Unverified2026-07-06WordPress Ninja Forms Plugin Unauthenticated File Upload — CVE-2026-0740 EPSS 63%
CVE-2026-0740 web Unverified
CVE-2026-0740webHIGHUnverified2026-07-05WordPress "Drag and Drop File Upload for Contact Form 7" Unauthenticated RCE — CVE-2026-5364
CVE-2026-5364 web Unverified
CVE-2026-5364webHIGH 8.1Unverified2026-07-05WebStack WordPress Theme Unauthenticated Arbitrary File Upload RCE — CVE-2026-1555
CVE-2026-1555 web Unverified
CVE-2026-1555webCRITICAL 9.8Unverified2026-07-05Visitor Management System 1.0 — Unrestricted File Upload to RCE (CVE-2026-37748)
CVE-2026-37748 web Unverified
CVE-2026-37748webHIGH 7.2Unverified2026-07-05User Registration Advanced Fields WordPress Plugin Unauthenticated Arbitrary File Upload (CVE-2026-4882)
CVE-2026-4882 web Unverified
CVE-2026-4882webCRITICAL 9.8Unverified2026-07-05Piotnet Addons for Elementor Pro Unauthenticated Arbitrary File Upload RCE (CVE-2026-4885)
CVE-2026-4885 web Unverified
CVE-2026-4885webCRITICALUnverified2026-07-05midi-Synth WordPress Plugin Arbitrary File Upload (CVE-2026-1306)
CVE-2026-1306 web Unverified
CVE-2026-1306webCRITICAL 9.8Unverified2026-07-05Mercator Configuration SSRF Chained to Internal Redis RCE (CVE-2026-49345)
CVE-2026-49345 web Unverified
CVE-2026-49345webCRITICALUnverified2026-07-05KnowledgeDeliver ASP.NET ViewState Deserialization RCE via Hardcoded Machine Keys — CVE-2026-5426
CVE-2026-5426 web Unverified
CVE-2026-5426webCRITICALUnverified2026-07-05Kanboard — Missing Access Control on Plugin Installation Leads to Administrative RCE via Webshell Plugin (CVE-2026-25924)
CVE-2026-25924 / GHSA-grch-p7vf-vc4f web Patched
CVE-2026-25924 / GHSA-grch-p7vf-vc4fwebHIGH 8.4Patched2026-07-05FUXA SCADA/HMI — Unauthenticated Path Traversal to Remote Code Execution (CVE-2026-25895) EPSS 11%
CVE-2026-25895 web Patched
CVE-2026-25895webCRITICAL 9.8Patched2026-07-05FreeScout Zero-Click RCE via Email Attachment Filename Sanitization Bypass ("Mail2Shell") — CVE-2026-28289 EPSS 31%
CVE-2026-28289 web Patched
CVE-2026-28289webCRITICAL 10Patched2026-07-05EspoCRM Authenticated RCE via Formula ACL Bypass + Attachment Path Traversal — CVE-2026-33656
CVE-2026-33656 web Patched
CVE-2026-33656webCRITICALPatched2026-07-05Discuz! X5.0 Race Condition + CAPTCHA-Solving Pre-Auth to RCE Chain (CVE-2026-49952)
CVE-2026-49952 (chain also referenced as KIS-2026-09, KIS-2026-10, KIS-2026-11) web Unverified
CVE-2026-49952webCRITICALUnverified2026-07-05Control Web Panel Pre-Auth Blind SQL Injection to RCE — CVE-2026-57517
CVE-2026-57517 web Patched
CVE-2026-57517webCRITICAL 9.8Patched2026-07-05Chamilo LMS Authenticated RCE via Unrestricted File Upload — CVE-2026-29041
CVE-2026-29041 web Patched
CVE-2026-29041webHIGH 8.8Patched2026-07-05Bludit CMS API Unrestricted File Upload to RCE (CVE-2026-25099)
CVE-2026-25099 web Patched
CVE-2026-25099webHIGHPatched2026-07-05Unauthenticated RCE in Joomla Content Editor (JCE) Profile Import (CVE-2026-48907) KEV EPSS 78%
CVE-2026-48907 web Patched
CVE-2026-48907webCRITICAL 10Patched2026-07-01Cisco Unified CM WebDialer SSRF to Arbitrary File Write / RCE (CVE-2026-20230) KEV EPSS 88%
CVE-2026-20230 network Unverified
CVE-2026-20230networkCRITICAL 8.6Unverified2026-07-01