CVE Arsenal

Critical Vulnerability Research & Exploitation

gotr00t@arsenal:~$ Loading discovered vulnerabilities...

CRITICAL
CVE-2026-39808
Critical
Fortinet FortiSandbox Unauthenticated OS Command Injection
Critical unauthenticated OS command injection in Fortinet FortiSandbox (4.4.0–4.4.8). An unsanitized jid parameter in the /fortisandbox/job-detail/tracer-behavior endpoint lets an attacker inject arbitrary OS commands; the output is written to a web-accessible file and retrieved without authentication.
Year
2026
Type
Command Injection
Impact
Critical
Repo
CVE-2026-39808
HIGH
CVE-2025-14847
CVSS 8.7
MongoDB Memory Leak (MongoBleed)
High-severity vulnerability in MongoDB that allows unauthenticated attackers to read uninitialized heap memory from MongoDB servers. Exploits improper handling of length parameter inconsistencies in Zlib-compressed protocol headers (OP_COMPRESSED messages). Can leak sensitive in-memory data including credentials, API keys, tokens, and encryption keys.
Year
2025
Type
Memory Leak
Impact
High
Stars
⭐ 0
CRITICAL
CVE-2025-24893
CVSS 9.8
XWiki Server-Side Template Injection RCE
Critical Server-Side Template Injection (SSTI) vulnerability in XWiki via Groovy template injection in the SolrSearch RSS feed endpoint. Allows unauthenticated remote code execution with full system access.
Year
2025
Type
SSTI/RCE
Impact
Critical
Stars
⭐ 0
CRITICAL
CVE-2024-4040
CVSS 9.8
CrushFTP Server Side Template Injection
Critical Server Side Template Injection (SSTI) vulnerability in CrushFTP that allows remote code execution through template manipulation. Affects multiple versions and can lead to complete system compromise with administrative privileges.
Year
2024
Type
SSTI/RCE
Impact
Critical
Stars
⭐ 8
CRITICAL
CVE-2023-43208
CVSS 9.8
NextGen Mirth Connect Pre-Auth RCE
Pre-authentication Remote Code Execution vulnerability in NextGen Mirth Connect that allows attackers to execute arbitrary code without authentication. Critical severity with widespread impact on healthcare systems.
Year
2023
Type
Pre-Auth RCE
Impact
Critical
Stars
⭐ 4
CRITICAL
CVE-2024-4577
CVSS 9.8
PHP CGI Argument Injection RCE
Critical argument injection vulnerability in PHP CGI affecting Windows systems when using certain locale settings. Allows remote code execution through crafted HTTP requests.
Year
2024
Type
CGI RCE
Impact
Critical
Repo
CVE-2024-4577
CRITICAL
CVE-2024-55591
CVSS 9.6
Fortinet FortiOS & FortiProxy Authentication Bypass
Critical authentication bypass in FortiOS and FortiProxy via the Node.js websocket module. Allows a remote attacker to gain super-admin privileges through crafted requests. Actively exploited in the wild against internet-facing Fortinet appliances.
Year
2024
Type
Auth Bypass
Impact
Critical
Repo
CVE-2024-55591
CRITICAL
CVE-2022-1388
CVSS 9.8
F5 BIG-IP iControl REST API Authentication Bypass
Critical authentication bypass vulnerability in F5 BIG-IP iControl REST API that allows unauthenticated remote code execution with administrative privileges.
Year
2022
Type
Auth Bypass
Impact
Critical
Stars
⭐ 5
CRITICAL
CVE-2025-29927
CVSS 9.1
Next.js Middleware Authorization Bypass
Authorization bypass vulnerability in Next.js middleware that allows attackers to access protected routes by manipulating request headers and bypassing security controls.
Year
2025
Type
Auth Bypass
Impact
Critical
Repo
CVE-2025-29927
HIGH
Ivanti_PoC
High Impact
Ivanti Endpoint Manager Mobile Authentication Bypass
Authentication bypass vulnerability in Ivanti Endpoint Manager Mobile (EPMM) that allows unauthorized access to administrative functions and sensitive enterprise data.
Year
2024
Type
Auth Bypass
Impact
High
Stars
⭐ 3
MEDIUM
CVE-2024-45440
CVSS 5.3
Drupal 11.x-dev Full Path Disclosure
Information disclosure vulnerability in Drupal 11.x-dev that exposes sensitive file system paths through the authorize.php endpoint. The vulnerability allows attackers to discover server directory structures, settings.php locations, and potentially sensitive configuration file paths without authentication.
Year
2024
Type
Info Disclosure
Impact
Medium
Target
Drupal
ARSENAL
3xplo1tz
Multi-CVE
Advanced Exploitation Collection
Comprehensive collection of 10 advanced proof-of-concept exploits including CVE-2025-31161, CVE-2024-4879, CVE-2024-28995, CVE-2024-0204, CVE-2023-30258, MS15-034, Shellshock, SpringBoot, TeamCity, and Zyxel PoC. Multi-platform exploitation toolkit for security research.
Exploits
10 PoCs
Type
Multi-Vector
Impact
Various
Collection
Research