tag
Zero-Click
PrestaShop Checkout Zero-Click Account Takeover via ExpressCheckout Endpoint (CVE-2025-61922)
The PrestaShop Checkout module exposes an ExpressCheckout endpoint (/module/pscheckout/ExpressCheckout) that is meant to handle PayPal Express Checkout order confirmation callbacks. Versions of the module prior to 5.0.5 fail to properly verify that the caller…
Dolby Unified (DDPlus) Decoder Out-of-Bounds Write via Evolution Data (CVE-2025-54957)
CVE-2025-54957 is a critical out-of-bounds write vulnerability in Dolby's DDPlus Unified Decoder, triggered while processing "evolution" data in an AC-3/EC-3 (Dolby Digital Plus) bitstream. An integer overflow in the length calculation for evolution-data…
Windows Shell LNK _IDCONTROLW Zero-Click SMB Coercion Builder — CVE-2026-32202
This repository documents a reverse-engineered, undocumented IDCONTROLW structure used internally by shell32.dll to represent Control Panel applet items inside a .lnk file's LinkTargetIDList, based on the researcher's own IDA Pro static analysis and…
libopenapv / Android APV Codec Zero-Click Heap Buffer Overflow (CVE-2026-0006)
The APV decoder in libopenapv parses two different structures — an AUINFO PBU (Payload Byte Unit) and the actual FRAME PBU — to determine frame dimensions, but oapvdinfo() and oapvddecode() read those dimensions from different sources without cross-validating…
FreeScout Zero-Click RCE via Email Attachment Filename Sanitization Bypass ("Mail2Shell") — CVE-2026-28289
FreeScout automatically saves incoming email attachments to a predictable, web-accessible storage path, and attempts to block dangerous filenames such as .htaccess. This PoC bypasses that filter by prepending a zero-width Unicode character to the .htaccess…
Windows NTLM Hash Disclosure via File Explorer - CVE-2025-24054
CVE-2025-24054 is a zero-click NTLMv2-SSP hash disclosure vulnerability in Windows File Explorer. When a user opens a ZIP archive containing a crafted .searchConnector-ms file, Windows Explorer automatically resolves an embedded UNC path during file preview,…
Windows OLE Zero-Click RCE via Outlook RTF (CVE-2025-21298)
CVE-2025-21298 is a critical Windows OLE memory-corruption vulnerability in ole32.dll that can be triggered through malicious RTF content. In Outlook scenarios, preview-pane rendering is sufficient to trigger the vulnerable parsing flow, making this…