PoC Archive PoC Archive

tag

Zero-Click

PrestaShop Checkout Zero-Click Account Takeover via ExpressCheckout Endpoint (CVE-2025-61922)
CVE-2025-61922 web Patched
CVE-2025-61922webCRITICAL 9.1Patched2026-07-06Dolby Unified (DDPlus) Decoder Out-of-Bounds Write via Evolution Data (CVE-2025-54957)
CVE-2025-54957 binary Unverified
CVE-2025-54957binaryCRITICAL 9.8Unverified2026-07-06Windows Shell LNK _IDCONTROLW Zero-Click SMB Coercion Builder — CVE-2026-32202 KEV EPSS 64%
CVE-2026-32202 (related: CVE-2026-21510) binary Unverified
CVE-2026-32202binaryHIGHUnverified2026-07-05libopenapv / Android APV Codec Zero-Click Heap Buffer Overflow (CVE-2026-0006)
CVE-2026-0006 binary Unverified
CVE-2026-0006binaryCRITICAL 9.8Unverified2026-07-05FreeScout Zero-Click RCE via Email Attachment Filename Sanitization Bypass ("Mail2Shell") — CVE-2026-28289 EPSS 31%
CVE-2026-28289 web Patched
CVE-2026-28289webCRITICAL 10Patched2026-07-05Windows NTLM Hash Disclosure via File Explorer - CVE-2025-24054 KEV EPSS 59%
CVE-2025-24054 binary Unverified
CVE-2025-24054binaryMEDIUM 6.5Unverified2026-05-17Windows OLE Zero-Click RCE via Outlook RTF (CVE-2025-21298) EPSS 81%
CVE-2025-21298 binary Patched
CVE-2025-21298binaryCRITICAL 9.8Patched2026-05-16