• XSS.stack #1 – первый литературный журнал от юзеров форума

Remote Top 10 Most Recent Unauthenticated RCE Exploits (with CVEs)

Wiz

Cyber War Leader
Пользователь
Регистрация
25.03.2022
Сообщения
509
Реакции
83
Гарант сделки
8
Here’s a curated list of the most recent unauthenticated remote code execution (RCE) vulnerabilities (CVE-listed). These issues allow attackers to execute arbitrary code without valid credentials, and many are already being actively exploited.

If anybody wants to share each poc exploits, it would be very good for our fellows.


#CVE ID(s)Product / ComponentSummary
1CVE-2025-53770Microsoft SharePoint ServerToolShell exploit: auth bypass via ToolPane.aspx, enables web-shell upload & secret theft
2CVE-2025-47812Wing FTP ServerNull-byte injection leads to Lua RCE as SYSTEM/root; actively exploited in the wild
3CVE-2025-23319 / 23320 / 23334NVIDIA Triton Inference ServerChained Python backend flaws lead to unauthenticated full-server RCE
4CVE-2025-32433Erlang/OTP SSH ServerSSH message handling flaw allows pre-auth RCE (CVSS 10.0)
5CVE-2025-20337Cisco ISEAPI-based unauthenticated RCE yielding root
6CVE-2025-3248Langflow (low-code LLM framework)Critical RCE via unauthenticated request
7CVE-2025-29306FoxCMS v1.2.5Unsafe handling of id parameter leads to RCE
8CVE-2025-20281Cisco ISE (older issue)Another critical API-based unauthenticated RCE in ISE
9CVE-2025-53771SharePoint ServerReferer header spoof for authentication bypass, likely related to ToolShell chain
10CVE-2025-24813(unspecified; generic)Path equivalence flaw enabling RCE & file injection
 


Напишите ответ...
  • Вставить:
Прикрепить файлы
Верх