PoC Week 2026-07-20
The most featured CVEs in this week’s security newsletters, with public Proof-of-Concepts, ordered by mention count.
For the most up-to-date and accurate info, visit the NIST links. Always audit PoCs thoroughly before running them. I don’t vouch for any links in this list: follow them with caution.
CVE-2020-1938 Severity: 9.8 CRITICAL Impacted Products: Apache Tomcat Description: A vulnerability exists within the AJP Connector in Tomcat because the default configuration allows AJP connections to have higher trust and it is also enabled to listen on all configured IP addresses.…
Read more ⟶
PoC Week 2026-07-13
The most featured CVEs in this week’s security newsletters, with public Proof-of-Concepts, ordered by mention count.
For the most up-to-date and accurate info, visit the NIST links. Always audit PoCs thoroughly before running them. I don’t vouch for any links in this list: follow them with caution.
CVE-2026-56290 NEW Severity: 9.8 CRITICAL Impacted Products: Joomla extension Page Builder CK Description: The Joomla extension Page Builder CK is vulnerable to an unauthenticated arbitrary file upload that allows uploading executable files and leads to full RCE.…
Read more ⟶
PoC Week 2026-07-06
The most featured CVEs in this week’s security newsletters, with public Proof-of-Concepts, ordered by mention count.
For the most up-to-date and accurate info, visit the NIST links. Always audit PoCs thoroughly before running them. I don’t vouch for any links in this list: follow them with caution.
CVE-2026-46817 NEW Severity: 9.8 CRITICAL Impacted Products: Oracle Payments 12.2.3 through 12.2.15 Description: Oracle Payments, a component of Oracle E-Business Suite, is affected by a vulnerability in its File Transmission component that allows an unauthenticated remote attacker to take full control of the application.…
Read more ⟶
PoC Week 2026-06-29
The most featured CVEs in this week’s security newsletters, with public Proof-of-Concepts, ordered by mention count.
For the most up-to-date and accurate info, visit the NIST links. Always audit PoCs thoroughly before running them. I don’t vouch for any links in this list: follow them with caution.
CVE-2026-50656 NEW Severity: 7.8 HIGH Impacted Products: Microsoft Defender Description: Microsoft Defender is affected by a race condition vulnerability that allows an attacker to escalate privileges to SYSTEM level.…
Read more ⟶
PoC Week 2026-06-22
The most featured CVEs in this week’s security newsletters, with public Proof-of-Concepts, ordered by mention count.
For the most up-to-date and accurate info, visit the NIST links. Always audit PoCs thoroughly before running them. I don’t vouch for any links in this list: follow them with caution.
CVE-2026-11645 Severity: 9.6 CRITICAL Impacted Products: Google Chrome 149.0.7827.103 Description: Google Chrome versions prior to 149.0.7827.103 are affected by an out-of-bounds read and write vulnerability in the V8 JavaScript engine.…
Read more ⟶
PoC Week 2026-06-15
The most featured CVEs in this week’s security newsletters, with public Proof-of-Concepts, ordered by mention count.
For the most up-to-date and accurate info, visit the NIST links. Always audit PoCs thoroughly before running them. I don’t vouch for any links in this list: follow them with caution.
CVE-2026-47291 NEW Severity: 9.8 CRITICAL Impacted Products: Microsoft Windows Server 2025, version 10.0.26100.32995 Description: Microsoft Windows Server 2025 is affected by an integer overflow vulnerability in the Windows HTTP Protocol Stack (http.…
Read more ⟶
PoC Week 2026-06-08
The most featured CVEs in this week’s security newsletters, with public Proof-of-Concepts, ordered by mention count.
For the most up-to-date and accurate info, visit the NIST links. Always audit PoCs thoroughly before running them. I don’t vouch for any links in this list: follow them with caution.
CVE-2026-0257 NEW Severity: 9.1 CRITICAL Impacted Products: Palo Alto Networks PAN-OS, Prisma Access Description: Palo Alto Networks PAN-OS and Prisma Access are affected by an authentication bypass vulnerability in the GlobalProtect portal and gateway components.…
Read more ⟶
PoC Week 2026-06-01
The most featured CVEs in this week’s security newsletters, with public Proof-of-Concepts, ordered by mention count.
For the most up-to-date and accurate info, visit the NIST links. Always audit PoCs thoroughly before running them. I don’t vouch for any links in this list: follow them with caution.
CVE-2026-45498 NEW Severity: 6.1 MEDIUM Impacted Products: Microsoft Defender Description: Microsoft Defender is affected by a security bypass vulnerability, known as UnDefend, that allows a local standard user to prevent the software from receiving definition updates.…
Read more ⟶
PoC Week 2026-05-25
The most featured CVEs in this week’s security newsletters, with public Proof-of-Concepts, ordered by mention count.
For the most up-to-date and accurate info, visit the NIST links. Always audit PoCs thoroughly before running them. I don’t vouch for any links in this list: follow them with caution.
CVE-2026-43500 NEW Severity: 7.8 HIGH Impacted Products: Linux kernel Description: The Linux kernel is affected by a local privilege escalation vulnerability in the RxRPC subsystem, part of a vulnerability chain known as “Dirty Frag,” which allows an unprivileged local user to gain root access.…
Read more ⟶
PoC Week 2026-05-18
The most featured CVEs in this week’s security newsletters, with public Proof-of-Concepts, ordered by mention count.
For the most up-to-date and accurate info, visit the NIST links. Always audit PoCs thoroughly before running them. I don’t vouch for any links in this list: follow them with caution.
CVE-2026-42945 Severity: 8.1 HIGH Impacted Products: NGINX Plus, NGINX Open Source Description: NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_rewrite_module module.…
Read more ⟶