Exploit para CVE-2026-4480: inyeccion de comandos en la variable %J del print command de Samba para RCE sin autenticacion via spoolss.
-
Updated
Oct 3, 2026 - Python
Exploit para CVE-2026-4480: inyeccion de comandos en la variable %J del print command de Samba para RCE sin autenticacion via spoolss.
CVE-2023-26269: Misconfigured JMX in Apache James
MAL-004: Command Injection Bypass for CVE-2020-12641 in Roundcube Webmail
CVE-2026-55579 – Unauthenticated RCE in Pheditor via hardcoded default password "admin". Full Python exploit with file upload & terminal execution. No dependencies.
Case Study: SSHtranger Things (CVE-2019-6111, CVE-2019-6110) in Cisco SD-WAN
Mass Exploiter for CVE-2026-49049
CVE-2026-23550 - Modular DS WordPress Plugin **Unauthenticated Admin Access**
CVE-2026-58138 — Conductor (3.21.21..<3.30.2) unauthenticated RCE via INLINE GraalVM evaluator (HostAccess.ALL). Lab + PoC, verified e2e (root).
Critical RCE vulnerability (CVSS 9.3) in Weaver E-cology platform versions prior to build 20260312. Unauthenticated remote code execution via exposed debug endpoint at /papi/esearch/data/devops/dubboApi/debug/method. Comprehensive analysis, proof-of-concept, and detection guidance included.
CVE-2026-56782 — Gorse <0.5.10 unauthenticated DB dump/restore (admin_api_key fail-open). Lab + PoC, verified e2e.
CVE-2019-12409: RCE Vulnerability Due to Bad Defalut Config in Apache Solr
CVE-2016-15042 lab: Dockerized WordPress PoC for unauthenticated file upload in Frontend File Manager <4.0 and N‑Media Post Front‑end Form <1.1
MAL-012: Reflected Cross-Site Scripting in Admin Console leading to Remote Code Execution in Payara Server
CVE-2026-95675 · POC
Aimy Captcha-Less Form Guard Joomla Component PHP Object Injection RCE. clfgd XOR keystream recovery + unserialize(). CVSS 10.0 | CWE-502 | aimy_captcha-less_form_guard < 20.1
DJ-Classifieds Joomla Component Unauthenticated File Upload RCE. 3-string filter bypass via PHP short tags. CVSS 10.0 | CWE-434 | com_djclassifieds < 3.11.2
CVE-2021-46362: FreeMarker Server-Side Template Injection in Magnolia CMS
CVE-2026-58138 — Conductor (3.21.21..<3.30.2) unauthenticated RCE via INLINE GraalVM evaluator (HostAccess.ALL). Lab + PoC, verified e2e (root).
NTP is not authenticated... but trusted
To associate your repository with the unauthenticated topic, visit your repo's landing page and select "manage topics."