PoC Week 2025-03-24


The most featured CVEs in this week’s security newsletters, with public Proof-of-Concepts, ordered by mention count. Older CVEs, trivially exploitable vulnerabilities (such as using hard-coded credentials) and those affecting open source projects with very small userbases aren’t listed. For the most up-to-date and accurate info, visit the NIST links. Always audit PoCs thoroughly before running them. CVE-2024-8999 Severity: 9.8 CRITICAL Impacted Products: lunary-ai/lunary version v1.4.25 Description: improper access control vulnerability in the POST /api/v1/data-warehouse/bigquery endpoint.…
Read more ⟶

PoC Week 2025-03-17


The most featured CVEs in this week’s security newsletters, with public Proof-of-Concepts, ordered by mention count. Older CVEs, trivially exploitable vulnerabilities (such as using hard-coded credentials) and those affecting open source projects with very small userbases aren’t listed. For the most up-to-date and accurate info, visit the NIST links. Always audit PoCs thoroughly before running them. Slow week; just 2 from last year. CVE-2024-30043 Severity: 7.…
Read more ⟶

PoC Week 2025-03-10


The most featured CVEs in this week’s security newsletters, with public Proof-of-Concepts, ordered by mention count. Older CVEs, trivially exploitable vulnerabilities (such as using hard-coded credentials) and those affecting open source projects with very small userbases aren’t listed. For the most up-to-date and accurate info, visit the NIST links. Always audit PoCs thoroughly before running them. CVE-2025-27364 Severity: 10 CRITICAL Impacted Products: MITRE Caldera through 4.2.0 and 5.…
Read more ⟶

PoC Week 2025-03-03


The most featured CVEs in this week’s security newsletters, with public Proof-of-Concepts, ordered by mention count. Older CVEs, trivially exploitable vulnerabilities (such as using hard-coded credentials) and those affecting open source projects with very small userbases aren’t listed. For the most up-to-date and accurate info, visit the NIST links. Always audit PoCs thoroughly before running them. CVE-2024-54820 Severity: 9.8 CRITICAL Impacted Products: XOne Web Monitor v02.10.2024.530 framework 1.…
Read more ⟶

PoC Week 2025-02-24


The most featured CVEs in this week’s security newsletters, with public Proof-of-Concepts, ordered by mention count. Older CVEs, trivially exploitable vulnerabilities (such as using hard-coded credentials) and those affecting open source projects with very small userbases aren’t listed. For the most up-to-date and accurate info, visit the NIST links. Always audit PoCs thoroughly before running them. This one’s going out a few days late so will have some more recent CVEs.…
Read more ⟶

PoC Week 2025-02-17


The most featured CVEs in this week’s security newsletters, with public Proof-of-Concepts, ordered by mention count. Older CVEs, trivially exploitable vulnerabilities (such as using hard-coded credentials) and those affecting open source projects with very small userbases aren’t listed. For the most up-to-date and accurate info, visit the NIST links. Always audit PoCs thoroughly before running them. CVE-2024-21413 Severity: 9.8 CRITICAL Impacted Products: Microsoft Outlook Description: Microsoft Outlook Remote Code Execution Vulnerability.…
Read more ⟶

PoC Week 2025-02-10


The most featured CVEs in this week’s security newsletters, with public Proof-of-Concepts, ordered by mention count. Older CVEs, trivially exploitable vulnerabilities (such as using hard-coded credentials) and those affecting open source projects with very small userbases aren’t listed. For the most up-to-date and accurate info, visit the NIST links. Always audit PoCs thoroughly before running them. CVE-2024-55591 Severity: 9.8 CRITICAL Impacted Products: FortiOS version 7.0.0 through 7.0.16 and FortiProxy version 7.…
Read more ⟶

PoC Week 2025-02-03


The most featured CVEs in this week’s security newsletters, with public Proof-of-Concepts, ordered by mention count. Older CVEs, trivially exploitable vulnerabilities (such as using hard-coded credentials) and those affecting open source projects with very small userbases aren’t listed. For the most up-to-date and accurate info, visit the NIST links. Always audit PoCs thoroughly before running them. CVE-2024-57595 Severity: Awaiting analysis Impacted Products: DLINK DIR-825 REVB 2.03 devices Description: OS command injection vulnerability in the CGl interface apc_client_pin.…
Read more ⟶

PoC Week 2025-01-27


The most featured CVEs in this week’s security newsletters, with public Proof-of-Concepts, ordered by mention count. Older CVEs, trivially exploitable vulnerabilities (such as using hard-coded credentials) and those affecting open source projects with very small userbases aren’t listed. For the most up-to-date and accurate info, visit the NIST links. Always audit PoCs thoroughly before running them. CVE-2025-21298 Severity: 9.8 CRITICAL Impacted Products: Windows - various, see advisory Description: Windows OLE Remote Code Execution Vulnerability Remediation: Follow developer guidance.…
Read more ⟶

PoC Week 2025-01-20


The most featured CVEs in this week’s security newsletters, with public Proof-of-Concepts, ordered by mention count. Older CVEs, trivially exploitable vulnerabilities (such as using hard-coded credentials) and those affecting open source projects with very small userbases aren’t listed. For the most up-to-date and accurate info, visit the NIST links. Always audit PoCs thoroughly before running them. CVE-2024-55591 Severity: 9.8 CRITICAL Impacted Products: FortiOS version 7.0.0 through 7.0.16 and FortiProxy version 7.…
Read more ⟶