PoC Archive PoC Archive

tag

Zero-Click

  • CVE-2025-61922 web CRITICAL 9.1

    PrestaShop Checkout Zero-Click Account Takeover via ExpressCheckout Endpoint (CVE-2025-61922)

    The PrestaShop Checkout module exposes an ExpressCheckout endpoint (/module/pscheckout/ExpressCheckout) that is meant to handle PayPal Express Checkout order confirmation callbacks. Versions of the module prior to 5.0.5 fail to properly verify that the caller…

    Patched 2026-07-06
  • CVE-2025-54957 binary CRITICAL 9.8

    Dolby Unified (DDPlus) Decoder Out-of-Bounds Write via Evolution Data (CVE-2025-54957)

    CVE-2025-54957 is a critical out-of-bounds write vulnerability in Dolby's DDPlus Unified Decoder, triggered while processing "evolution" data in an AC-3/EC-3 (Dolby Digital Plus) bitstream. An integer overflow in the length calculation for evolution-data…

    Unverified 2026-07-06
  • CVE-2026-32202 binary HIGH KEV EPSS 64%

    Windows Shell LNK _IDCONTROLW Zero-Click SMB Coercion Builder — CVE-2026-32202

    This repository documents a reverse-engineered, undocumented IDCONTROLW structure used internally by shell32.dll to represent Control Panel applet items inside a .lnk file's LinkTargetIDList, based on the researcher's own IDA Pro static analysis and…

    Unverified 2026-07-05
  • CVE-2026-0006 binary CRITICAL 9.8

    libopenapv / Android APV Codec Zero-Click Heap Buffer Overflow (CVE-2026-0006)

    The APV decoder in libopenapv parses two different structures — an AUINFO PBU (Payload Byte Unit) and the actual FRAME PBU — to determine frame dimensions, but oapvdinfo() and oapvddecode() read those dimensions from different sources without cross-validating…

    Unverified 2026-07-05
  • CVE-2026-28289 web CRITICAL 10 EPSS 31%

    FreeScout Zero-Click RCE via Email Attachment Filename Sanitization Bypass ("Mail2Shell") — CVE-2026-28289

    FreeScout automatically saves incoming email attachments to a predictable, web-accessible storage path, and attempts to block dangerous filenames such as .htaccess. This PoC bypasses that filter by prepending a zero-width Unicode character to the .htaccess…

    Patched 2026-07-05
  • CVE-2025-24054 binary MEDIUM 6.5 KEV EPSS 59%

    Windows NTLM Hash Disclosure via File Explorer - CVE-2025-24054

    CVE-2025-24054 is a zero-click NTLMv2-SSP hash disclosure vulnerability in Windows File Explorer. When a user opens a ZIP archive containing a crafted .searchConnector-ms file, Windows Explorer automatically resolves an embedded UNC path during file preview,…

    Unverified 2026-05-17
  • CVE-2025-21298 binary CRITICAL 9.8 EPSS 81%

    Windows OLE Zero-Click RCE via Outlook RTF (CVE-2025-21298)

    CVE-2025-21298 is a critical Windows OLE memory-corruption vulnerability in ole32.dll that can be triggered through malicious RTF content. In Outlook scenarios, preview-pane rendering is sufficient to trigger the vulnerable parsing flow, making this…

    Patched 2026-05-16