TODO
Backlog
CVEs & Resources
- 2020
- [1]CVE-2020-3259 — Cisco AnyConnect
- 2021
- [2]CVE-2021-21985 — VMWare vSphere
- [3]CVE-2021-21972 — VMWare vCenter
- [4]CVE-2021-21974 — VMWare ESXi
- [5]CVE-2021-40655 — D-Link DIR-605L
- 2022
- [6]CVE-2022-22948 — VMWare vCenter
- 2023
- [7]CVE-2023-20198 — Cisco IOS XE
- [8]CVE-2023-20269 — Cisco ASA/Firepower VPN
- [9]CVE-2023-30908 — HPE OneView Auth Bypass
- [10]CVE-2023-34048 — VMWare vCenter
- [11]CVE-2023-34049 — VMWare Aria Operations for Networks
- [12]CVE-2023-48788 — Fortinet FortiClients EMS
- 2024
- [13]CVE-2024-3080 — ASUS Router Auth Bypass
- [14]CVE-2024-3400 — Palo Alto OS Command Injection
- [15]CVE-2024-3912 — ASUS Router Firmware Upload
- [16]CVE-2024-4985 — GitHub Enterprise Server Auth Bypass
- [17]CVE-2024-6045 — Confluence Auth RCE
- [18]CVE-2024-10914 — D-Link Command Injection
- [19]CVE-2024-20356 — Cisco CIMC Command Injection
- [20]CVE-2024-20357 — Cisco IP Phone XML Injection
- [21]CVE-2024-20358 — Cisco ASA/Firepower Auth RCE
- [22]CVE-2024-20359 — Cisco ASA/Firepower Auth RCE
- [23]CVE-2024-20419 — Cisco Smart Software Manager RCE
- [24]CVE-2024-24919 — Check Point SVN RCE
- [25]CVE-2024-29849 — Veeam Backup Auth Bypass
- [26]CVE-2024-29972 — Zyxel NAS326 Backdoor
- [27]CVE-2024-29973 — Zyxel NAS326 Code Injection
- [28]CVE-2024-29974 — Zyxel NAS326 RCE
- [29]CVE-2024-29975 — Zyxel NAS326 Priv Esc
- [30]CVE-2024-47575 — FortiJump Unauth RCE
- [31]CVE-2024-50629~50631 — Synology BeeStation RCE
- [32]PAN-SA-2024-0015 — Paloalto Unauth RCE
- [33]0.0.0.0-day — PNA bypass
- [34]Attacking UNIX Systems via CUPS
- 2025
- [35]CVE-2025-20188 — Cisco IOS XE Hardcoded JWT
- [36]CVE-2025-3280X — Kea DHCP Auth Bypass
- [37]CVE-2025-5054 — Apport Information Disclosure
- [38]CVE-2025-6218 — WinRAR Path Traversal RCE
- [39]CVE-2025-8110 — Gogs Path Traversal RCE
- [40]CVE-2025-13915 — IBM API Connect Auth Bypass
- [41]CVE-2025-14733 — WatchGuard Fireware OS Unauth RCE
- [42]CVE-2025-20393 — Cisco Secure Email Gateway RCE
- [43]CVE-2025-37164 — HPE OneView Unauth RCE
- [44]CVE-2025-52691 — SmarterMail Unauth RCE
- [45]CVE-2025-53690 — Sitecore Initial Access
- [46]CVE-2025-53772 — Microsoft Web Deploy RCE
- [47]CVE-2025-55182 — React RSC Code Execution
- [48]CVE-2025-59466 — Node.js DoS via async_hooks
- [49]CVE-2025-59470 — Veeam Auth RCE
- [50]CVE-2025-59718 / CVE-2025-59719 — Fortinet SSO Auth Bypass
- [51]CVE-2025-64155 — FortiSIEM Unauth RCE
- [52]CVE-2025-66516 — Apache Tika XXE
- [53]CVE-2025-68613 — n8n Code Execution
- [54]CVE-2025-68664 — LangChain Serialization Injection
- [55]CVE-2025-68668 — n8n Auth Sandbox Bypass
- [56]CVE-2026-0625 — D-Link Unauth Command Injection
- [57]CVE-2026-21858 — n8n Unauth RCE
- [58]CVE-2026-22709 — Node.js vm2 Sandbox Escape RCE
- [59]CVE-2026-24423 — SmarterMail Unauth RCE
- [60]CVE-xxxx-xxxxx — SmarterMail Auth Bypass
- [61]Hardware — Digital Microscope (budget)
- [62]Hardware — Digital Microscope (premium)
- [63]TP-Link Tapo C200 — Hardcoded Keys
- [64]XML Signature Wrapping (XSW)
- [65].NET Remote Object WSDL RCE
- 2026
- [66]CVE-2026-3888 — Ubuntu systemd Privilege Escalation
- [67]CVE-2026-21962 — Oracle Weblogic Proxy Plug-in Injection
- [68]CVE-2026-21992 — Oracle IDM RCE
- [69]CVE-2026-21994 — Oracle OKIT Hardcoded Flask Key
- [70]CVE-2026-23408 — AppArmor Use-After-Free LPE
- [71]CVE-2026-24061 — GNU InetUtils Telnetd Unauth RCE
- [72]CVE-2026-32746 — Telnetd Out-of-Bounds Write RCE
- [73]CVE-2026-40176 / CVE-2026-40261 — PHP Composer RCE
- [74]CVE-2026-42945 — NGINX Rift, heap buffer overflow, RCE/DOS
- [75]CVE-2026-XXXXX — Drupal something, more info May 20