ZeroHour

Search: “exploitability”

71 stories in the last 30d

Researchers Use Claude to Port Pre-Auth RCE Exploit From One PLC Model to Another

Forescout used Anthropic's Claude to port a working pre-auth RCE exploit for CVE-2021-31886 between WAGO PLCs, executing ARM shellcode on live hardware.

Forescout Vedere Labs used Claude interactively to port an RCE exploit for CVE-2021-31886, a CVSS 9.8 stack buffer overflow in the Nucleus FTP server's USER command, from a WAGO 750-852 to a WAGO 750-831 PLC, running attacker-supplied ARM shellcode. The final RCE stage cost $535.74 in API usage over 8 hours 32 minutes, and a follow-up attempt to build a C2 implant permanently bricked the device. CERT@VDE lists many Nucleus V1-based WAGO models as vulnerable with no updates available; Siemens plans no Nucleus NET remediation. The work follows a joint NSA/CISA/FBI/DOE/EPA advisory warning of AI-generated exploitation scripts targeting internet-exposed Siemens S7 PLCs.

The Hacker News · 14d agoResearchCVE-2021-318862

Forgery of C2PA on a Pixel 10

Researcher forged a Google Pixel 10 C2PA content credential with genuine signatures, showing root-level attackers can fake photo provenance.

A Hacker Factor blog post demonstrates an AI-generated 'unicorn glitter milk' news photo carrying a valid, cryptographically signed C2PA manifest traceable to Google's Pixel camera certificate chain, passing validation in Adobe Inspect and the CAI Verify tool with a verified timestamp. The author, working with UMBC's PASAWG working group, reported to Google and C2PA in November 2025 that root access on a Pixel device could sign arbitrary images as camera captures; after 90 days without resolution, details were published. The finding undermines C2PA Assurance Level 2 claims made for Pixel 10 Content Credentials.

Lobsters · security · 7h agoResearch

add a DefangedMode advanced options as teh exploit modifies the targe…

A Metasploit Framework commit adds a DefangedMode advanced option to an exploit module that modifies the target host configuration.

The commit introduces a DefangedMode advanced option so that the exploit's modification of the target configuration runs only explicitly, making the behavior visible to the user. No target product, affected software, or CVE identifier is named in the commit message.

Metasploit Framework commits · 14d agoExploit / PoC1

Deceptive Android Apps Exploit Google Play Early Access to Evade Reviews

Bitdefender reports deceptive Google Play Early Access apps use deepfake celebrity ads and fake rewards to lure users into ad-fraud schemes.

Bitdefender research describes widespread abuse of Google Play's Early Access program, where developers publish deceptive apps that avoid public ratings and reviews. The apps are promoted through TikTok and Facebook ads promising cash rewards, PayPal payouts, crypto earnings, or gift cards, often using deepfakes of celebrities, but users receive only aggressive advertising. Examples include 'Chicken Road' and 'Ice Fishing' casino-style games plus trademark abuse such as apps named 'Grand Theft Auto V (Early Access)' that are later renamed. No malware is delivered, but some listings show thousands of installs.

SecurityWeekupdated · 5d agofirst · 6d agoPhishing & fraud in the wild 6 sources

Muhstik Botnet Attacks Tomato Routers to Harvest New IoT Devices

Unit 42 found a Muhstik botnet variant brute-forcing Tomato router web authentication to harvest IoT devices for crypto mining and DDoS attacks.

Palo Alto Networks Unit 42 researchers in December 2019 identified a new Muhstik botnet variant scanning Tomato routers on TCP 8080 and brute-forcing default admin credentials, targeting roughly 4,600 exposed devices found via Shodan. The variant also scans WordPress and Webuzo installations and exploits the Oracle WebLogic deserialization flaw CVE-2019-2725 for unauthenticated remote code execution. Muhstik, active since March 2018, self-propagates like a worm and typically monetizes infections through cryptocurrency mining and DDoS attacks controlled via an IRC C2 channel.

Palo Alto Unit 42 · 28d agoMalware in the wildCVE-2019-2725

Cisco Industrial Ethernet 1000 Series Switches Stored Cross-Site Scripting Vulnerability

Cisco fixed a stored cross-site scripting flaw in Industrial Ethernet 1000 series switches exploitable by authenticated remote users.

Insufficient validation of user-supplied input in the web-based management interface of Cisco Industrial Ethernet 1000 Series Switches allows stored XSS. An authenticated remote attacker can inject malicious code into specific interface pages and execute arbitrary script in another user's context. Exploitation requires valid credentials; Cisco has released software updates.

Cisco Security Advisories · 28d agoAdvisory

CareCam Pro IP Cameras

CISA advisory details hard-coded bootloader credential CVE-2026-85083 in ANJIA AJL33PC0801 CareCam Pro cameras, allowing physical-access firmware compromise.

CISA ICS advisory ICSA-26-251-01 describes CVE-2026-85083, a hard-coded credential (CWE-798) used for bootloader authentication in the ANJIA AJL33PC0801 CareCam Pro IP camera. An attacker with physical access could gain privileged bootloader access and modify firmware and configuration, potentially fully compromising the device. The flaw scores 6.8 on CVSS 3.1 (7.0 on CVSS 4.0), is not remotely exploitable, and no public exploitation has been reported. Affected firmware is linux_linux_202008261138_svn13796 with U-Boot 2010.06; the vendor is headquartered in China with worldwide deployments.

CISA Advisories · 8d agoAdvisoryCVE-2026-85083

OPCFoundation OPC UA LocalDiscoveryServer (LDS)

CISA warns CVE-2026-77477 (CVSS 4.6) lets local attackers hijack a privileged console during OPC UA LDS installation below version 1.04.420.

CISA published ICSA-26-246-01 for CVE-2026-77477, CWE-250 execution with unnecessary privileges in OPC Foundation UA-LDS-Installers below 1.04.420. An attacker able to launch the installer with elevated privileges and access the keyboard and display can intercept a high-privilege console window during installation and run arbitrary commands. CVSS 3.1 score is 4.6, the issue is not remotely exploitable, and no public exploitation has been reported. Lukas Schumaker of Rockwell Automation reported the flaw to OPC Foundation.

CISA Advisories · 13d agoAdvisoryCVE-2026-77477

[webapps] PodcastGenerator 3.2.9 - Stored XSS

A stored cross-site scripting flaw in PodcastGenerator 3.2.9 is documented with a public proof-of-concept exploit on Exploit-DB.

Exploit-DB published exploit ID 52677 targeting PodcastGenerator 3.2.9, a web application affected by stored cross-site scripting. The listing provides a proof-of-concept for the flaw but includes no CVE identifier or reports of active exploitation.

Exploit-DB · 14d agoExploit / PoC1

[webapps] Bludit CMS 3.20.0 - Reflected Cross-Site Scripting

A reflected cross-site scripting flaw in Bludit CMS 3.20.0 is documented with a public proof-of-concept exploit on Exploit-DB.

Exploit-DB published exploit ID 52678 targeting Bludit CMS 3.20.0, a web application affected by reflected cross-site scripting. The listing contains a proof-of-concept but includes no CVE identifier or evidence of active exploitation.

Exploit-DB · 14d agoExploit / PoC

[webapps] EasyAppointments 1.5.1 - Blind SQL Injection

A proof-of-concept exploit for a blind SQL injection vulnerability in EasyAppointments 1.5.1 has been published on Exploit-DB.

Exploit-DB lists a public proof-of-concept exploit for a blind SQL injection flaw in EasyAppointments 1.5.1. The listing falls under the webapps category and enables reproduction of the injection. No in-the-wild exploitation or CVE identifier is stated in the listing.

Exploit-DB · 15d agoExploit / PoC1

[webapps] Wolf CMS 0.8.3.1 - RCE v

A proof-of-concept exploit for remote code execution in Wolf CMS 0.8.3.1 has been published on Exploit-DB.

Exploit-DB lists a public proof-of-concept exploit for a remote code execution vulnerability in Wolf CMS 0.8.3.1. The listing is categorized under web applications. No exploitation in the wild or CVE identifier is stated in the listing.

Exploit-DB · 15d agoExploit / PoC1

[webapps] miniOrange 5.4.3 - Unauthenticated Auth Bypass

A proof-of-concept exploit for an unauthenticated authentication bypass in miniOrange 5.4.3 has been published on Exploit-DB.

Exploit-DB lists a public proof-of-concept exploit for an unauthenticated authentication bypass in miniOrange 5.4.3. The flaw allows attackers to bypass authentication without credentials. No in-the-wild exploitation or CVE identifier is stated in the listing.

Exploit-DB · 15d agoExploit / PoC

[webapps] Grav CMS 2.0.7 - RCE

A proof-of-concept exploit for remote code execution in Grav CMS 2.0.7 has been published on Exploit-DB.

Exploit-DB lists a public proof-of-concept exploit for a remote code execution vulnerability in Grav CMS 2.0.7. The listing is for web applications and provides code defenders can use to reproduce the issue. No exploitation in the wild or CVE assignment is stated in the listing.

Exploit-DB · 15d agoExploit / PoC

[webapps] Payload CMS 3.72.0 - Blind SQL Injection

A proof-of-concept exploit for a blind SQL injection vulnerability in Payload CMS 3.72.0 has been published on Exploit-DB.

Exploit-DB lists a public proof-of-concept exploit for a blind SQL injection flaw in Payload CMS 3.72.0. The listing falls under the webapps category and allows reproduction of the injection. No in-the-wild exploitation or CVE identifier is stated in the listing.

Exploit-DB · 15d agoExploit / PoC1

[webapps] CubeCart 6.7.4 - SQL injection

A second proof-of-concept SQL injection exploit for CubeCart 6.7.4 was published on Exploit-DB.

Exploit-DB lists a SQL injection proof-of-concept affecting CubeCart 6.7.4, the open-source shopping cart application. The entry demonstrates the flaw but the provided text does not include a CVE identifier or reports of exploitation in the wild. It appears alongside related CubeCart XSS and SQL injection listings published the same day.

Exploit-DB · 16d agoExploit / PoC1

[webapps] CubeCart 6.7.4 - Stored XSS

A proof-of-concept stored cross-site scripting exploit targeting CubeCart 6.7.4 was published on Exploit-DB.

Exploit-DB lists a proof-of-concept exploit for a stored cross-site scripting (XSS) vulnerability in CubeCart 6.7.4, a PHP-based e-commerce web application. The listing demonstrates injection of attacker-controlled script that persists in the application, but no exploitation in the wild or CVE assignment is reported in the provided text.

Exploit-DB · 16d agoExploit / PoC1

[webapps] C-MOR 6.0104 - Cross-Site Scripting (XSS)

A proof-of-concept cross-site scripting exploit for C-MOR video surveillance software 6.0104 appeared on Exploit-DB.

Exploit-DB published a proof-of-concept cross-site scripting (XSS) exploit against C-MOR 6.0104, an IP video surveillance platform. The listing demonstrates script injection in the web interface, but the provided text contains no CVE identifier or indication of active exploitation. Successful XSS against the surveillance console could enable session hijacking or manipulation of the monitoring interface.

Exploit-DB · 16d agoExploit / PoC1

[webapps] CubeCart 6.7.4 - Cross-Site Scripting

A cross-site scripting exploit targeting CubeCart 6.7.4 web applications was published on Exploit-DB as entry 52661.

Exploit-DB listing 52661 discloses a cross-site scripting vulnerability in CubeCart version 6.7.4, classified under webapps. The listing makes a public exploit available, but no CVE id, exploitation evidence, or vendor patch status is provided in the item text.

Exploit-DB · 16d agoExploit / PoC

[webapps] CubeCart 6.7.4 - SQL

A proof-of-concept SQL injection exploit targeting CubeCart 6.7.4 was published on Exploit-DB.

Exploit-DB carries a proof-of-concept exploit for a SQL injection vulnerability in CubeCart 6.7.4, an open-source e-commerce platform. The listing demonstrates the injection issue but the provided text includes no CVE identifier or evidence of active exploitation. SQL injection in the storefront could expose or modify store data.

Exploit-DB · 16d agoExploit / PoC1

[webapps] Linuxfabrik monitoring_plugins_6.0.0 - SSRF

A public proof-of-concept exploit for an SSRF flaw in Linuxfabrik monitoring_plugins 6.0.0 appeared on Exploit-DB.

Exploit-DB listing 52653 discloses a server-side request forgery (SSRF) vulnerability in Linuxfabrik monitoring_plugins version 6.0.0, classified under web applications. A proof-of-concept exploit is publicly available. No CVE identifier or evidence of in-the-wild exploitation is provided in the listing.

Exploit-DB · 29d agoExploit / PoC

[webapps] flyto-core 2.26.7 - Arbitrary File Write

flyto-core 2.26.7 has an arbitrary file write vulnerability with a public proof-of-concept exploit on Exploit-DB.

Exploit-DB listing 52655 discloses an arbitrary file write vulnerability in flyto-core version 2.26.7. A proof-of-concept exploit is publicly available. The listing provides no CVE identifier and no indication of active exploitation; arbitrary file writes can potentially enable code execution depending on write locations.

Exploit-DB · 29d agoExploit / PoC

[remote] PCMan 2.0.7 - Buffer Overflow

A remote buffer overflow in PCMan 2.0.7 has a public proof-of-concept exploit published on Exploit-DB.

Exploit-DB listing 52657 discloses a remote buffer overflow vulnerability in PCMan version 2.0.7. A proof-of-concept exploit is publicly available, allowing attackers to potentially crash or compromise affected instances. The listing includes no CVE identifier and reports no observed exploitation in the wild.

Exploit-DB · 29d agoExploit / PoC1

Cisco Identity Services Engine Authorization Bypass Vulnerabilities

Cisco fixed authorization bypass flaws in ISE and ISE-PIC web management letting authenticated admins modify file descriptions via crafted HTTP requests.

Multiple vulnerabilities in the web-based management interface of Cisco Identity Services Engine and ISE Passive Identity Connector result from missing server-side validation of Administrator permissions. An authenticated remote attacker with valid Administrator credentials can submit crafted HTTP requests to modify descriptions of files on specific pages. Cisco has released software updates addressing the issues.

Cisco Nexus Dashboard Software Security Hardening Release: September 2026

Cisco released Nexus Dashboard hardening updates for multiple internally discovered vulnerabilities, grouped by CWE and not known to be exploited.

Cisco's Nexus Dashboard engineering team conducted an internal security review that found multiple vulnerabilities, addressed via software hardening releases. The issues were discovered during internal testing and are not known to be actively exploited. Cisco grouped the issues by CWE class and assigned a single CVE ID per issue before releasing fixes.

Re: Retrospective by 'gpg.fail' authors

GPG exploitation talk author clarifies a format-string 0day enabling code execution via printf %n writes and a polyglot PEM certificate payload.

Lexi Groves, author of the gpg.fail talk, clarified on oss-security that the first finding was an actual zero-day: a classic printf injection using %n for memory writes, with multiple X.509 certificates in one PEM file to re-enter and defeat ASLR before calling execv@plt. The payload executed the certificate itself, a polyglot file made by inserting a shebang and bash command into the PEM. A second finding was hash-collided by another party before the author could exploit it.

oss-securityupdated · 3h agofirst · 20h agoResearch 8 sources

Cisco IOS XR Software Security Hardening Release: September 2026

Cisco released IOS XR security hardening fixes for multiple internally discovered vulnerabilities, grouped by CWE class, with no known active exploitation.

Cisco's IOS XR engineering team conducted a comprehensive internal security review and released hardening updates addressing multiple internally discovered vulnerabilities. The issues were found during internal testing and are not known to be actively exploited. Cisco grouped the vulnerabilities by CWE class and assigned a single CVE ID to each grouping to streamline patching and disclosure.

Cisco Security Advisories · 12d agoAdvisory

ZDI-26-608: Linux Kernel KVM IOAPIC Use-After-Free Local Privilege Escalation Vulnerability

The Linux kernel KVM IOAPIC has a use-after-free (CVSS 8.2) allowing local privilege escalation, but exploitation requires high-privileged code execution first.

ZDI-26-608 describes a use-after-free vulnerability in the Linux kernel's KVM IOAPIC component, with a CVSS score of 8.2. An attacker must first obtain the ability to execute high-privileged code on the target system, which limits the practical impact of the privilege escalation. The advisory text does not list an assigned CVE identifier.

ZDI Published Advisories · 23d agoVulnerability

Cisco Unified Intelligence Center SQL Injection Vulnerability

Cisco patched a blind SQL injection in Unified Intelligence Center's web interface allowing authenticated local attackers to read the internal database.

Cisco disclosed a blind SQL injection vulnerability in the web-based management interface of Unified Intelligence Center, caused by insufficient validation of user-supplied input. An authenticated local attacker can send crafted requests and read the contents of the device's internal database. Exploitation requires valid user credentials, and Cisco has released software updates.

Cisco Security Advisories · 28d agoAdvisory

Cisco Secure Workload Software Security Hardening Release: August 2026

Cisco shipped August 2026 hardening releases for Secure Workload fixing multiple internally discovered vulnerabilities that are not actively exploited.

Cisco's Secure Workload engineering team completed an internal security review that found multiple vulnerabilities during internal testing. The issues are grouped by CWE class with a single CVE assigned per grouping, and none are known to be actively exploited. Cisco has released hardening updates for customers to patch.

Cisco Security Advisories · 28d agoAdvisory

Cisco BroadWorks CommPilot Application Software Authorization Bypass Vulnerability

Cisco patched a BroadWorks CommPilot authorization bypass letting low-privileged authenticated users alter device configurations via crafted HTTP requests.

A vulnerability in the web-based management interface of Cisco BroadWorks CommPilot Application Software is caused by missing authorization checks. An authenticated remote attacker with low privileges can send crafted HTTP requests to alter configurations on select pages. Cisco has released software updates and no workarounds are available.

VU#859658: Skullcandy Dime 3 wireless earbuds contain an unauthenticated Bluetooth pairing vulnerability

Skullcandy Dime 3 earbuds (CVE-2025-20701) accept Bluetooth pairings without owner consent, letting in-range attackers hijack audio or capture microphone; no firmware update path exists.

CERT/CC's VU#859658 describes CVE-2025-20701 in the Airoha Bluetooth audio SDK, present in Skullcandy Dime 3 (Model S2DCW) firmware 1.0.0.28. A direct Bluetooth Classic pairing request with no PIN or physical confirmation completes via NoInputNoOutput, adding the attacker's device as trusted. Attackers in radio range can hijack the A2DP audio session, access the Hands-Free/Headset profile, and capture live microphone audio. Firmware 1.0.0.30 contains the effective patch, but Skullcandy says the Dime 3 does not support app-based firmware updates, leaving existing units unpatchable.

Cisco Desk Phone 9800 Series, IP Phone 7800 and 8800 Series, and Video Phone 8875 with SIP Software Denial of Service Vulnerability

Cisco warns of a DoS flaw in SIP software on Desk Phone 9800 and IP Phone 7800/8800 series from improper HTTP packet memory handling.

Cisco disclosed a denial of service vulnerability affecting Desk Phone 9800 Series, IP Phone 7800 and 8800 Series, and Video Phone 8875 devices running Cisco SIP Software. An unauthenticated remote attacker can send a continuous stream of crafted HTTP packets, causing sustained memory consumption until the device becomes unresponsive. A manual reboot is required to recover an affected device. No CVE identifier was listed in the advisory text.

Cisco Security Advisories · 14d agoAdvisory

[dos] EVerest 2025.9.0 - DoS

A public proof-of-concept denial-of-service exploit has been published for the EVerest 2025.9.0 open-source EV charging framework.

Exploit-DB lists a denial-of-service proof of concept targeting EVerest version 2025.9.0. EVerest is an open-source software framework used for EV charging infrastructure. No in-the-wild exploitation or CVE mapping is stated in the listing.

Exploit-DB · 14d agoExploit / PoC1

[hardware] Fullhan FH8626V100 - Multiple Vulnerabilities

Multiple vulnerabilities in the Fullhan FH8626V100 hardware chip have been disclosed alongside public proof-of-concept exploits.

Exploit-DB lists an entry covering multiple vulnerabilities in the Fullhan FH8626V100, a hardware component. The listing provides no CVE ids, vulnerability classes, or evidence of in-the-wild exploitation. Impact is likely limited to devices embedding the affected chip.

Exploit-DB · 14d agoExploit / PoC

[webapps] Bludit CMS - Stored XSS

A stored cross-site scripting (XSS) vulnerability in Bludit CMS was disclosed through a public proof-of-concept published on Exploit-DB.

Exploit-DB published a webapps entry for a stored XSS flaw in Bludit CMS, an open-source flat-file content management system. Stored XSS allows an attacker to persist malicious scripts that execute in other users' browsers, potentially enabling session theft or unauthorized actions. The listing did not include a CVE identifier or affected version range.

Exploit-DB · 15d agoExploit / PoC1

[webapps] C-MOR 6.0104 - Directory Traversal

A directory traversal proof-of-concept for video surveillance software C-MOR version 6.0104 has been published on Exploit-DB.

Exploit-DB entry 52666 discloses a directory traversal vulnerability in C-MOR version 6.0104, a video surveillance platform. The issue is listed under web application vulnerabilities. No CVE identifier or exploitation evidence is included in the listing.

Exploit-DB · 16d agoExploit / PoC

Cisco Industrial Ethernet 1000 Series Switches Denial of Service Vulnerability

Cisco released a fix for a management-plane flooding DoS in IE-1000 switches that can make the device manager, SSH, or API inaccessible.

Insufficient protection against management plane flooding in Cisco Industrial Ethernet 1000 Series Switches allows an unauthenticated remote attacker to send high-rate ICMP, SSH, or HTTP traffic, raising CPU usage and causing a denial-of-service condition on the device manager web GUI, SSH, or API. Data traffic through the device is not affected. Cisco has released software updates to address the issue.

Cisco Security Advisories · 28d agoAdvisory

Cisco RoomOS Stack Overflow Vulnerability

Cisco fixed a stack overflow in the RoomOS USB driver allowing physical-access attackers to execute code with root privileges.

Insufficient boundary checks in the USB driver of Cisco RoomOS allow a buffer overflow when specific data is supplied through the USB port. An unauthenticated local attacker with physical access can connect a malicious USB device and execute arbitrary code with root privileges. Cisco has released software updates and no workarounds address the issue.

Cisco Security Advisories · 28d agoAdvisory

[dos] NanaZip 6.5 - DoS

A denial-of-service proof-of-concept targeting NanaZip 6.5 has been published on Exploit-DB.

Exploit-DB entry 52656 contains a public proof-of-concept that triggers a denial-of-service condition in NanaZip 6.5. The listing is limited to the vulnerability title and does not include CVE identifiers or details on exploitation conditions. No evidence of in-the-wild exploitation is provided.

Exploit-DB · 29d agoExploit / PoC