CVE Arsenal

Critical Vulnerability Research & Exploitation

gotr00t@arsenal:~$ Loading discovered vulnerabilities...

HIGH
CVE-2025-14847
CVSS 8.7
MongoDB Memory Leak (MongoBleed)
High-severity vulnerability in MongoDB that allows unauthenticated attackers to read uninitialized heap memory from MongoDB servers. Exploits improper handling of length parameter inconsistencies in Zlib-compressed protocol headers (OP_COMPRESSED messages). Can leak sensitive in-memory data including credentials, API keys, tokens, and encryption keys.
Year
2025
Type
Memory Leak
Impact
High
Stars
⭐ 0
CRITICAL
CVE-2025-24893
CVSS 9.8
XWiki Server-Side Template Injection RCE
Critical Server-Side Template Injection (SSTI) vulnerability in XWiki via Groovy template injection in the SolrSearch RSS feed endpoint. Allows unauthenticated remote code execution with full system access.
Year
2025
Type
SSTI/RCE
Impact
Critical
Stars
⭐ 0
CRITICAL
CVE-2024-4040
CVSS 9.8
CrushFTP Server Side Template Injection
Critical Server Side Template Injection (SSTI) vulnerability in CrushFTP that allows remote code execution through template manipulation. Affects multiple versions and can lead to complete system compromise with administrative privileges.
Year
2024
Type
SSTI/RCE
Impact
Critical
Stars
⭐ 8
CRITICAL
CVE-2023-43208
CVSS 9.8
NextGen Mirth Connect Pre-Auth RCE
Pre-authentication Remote Code Execution vulnerability in NextGen Mirth Connect that allows attackers to execute arbitrary code without authentication. Critical severity with widespread impact on healthcare systems.
Year
2023
Type
Pre-Auth RCE
Impact
Critical
Stars
⭐ 4
CRITICAL
CVE-2024-4577
CVSS 9.8
PHP CGI Argument Injection RCE
Critical argument injection vulnerability in PHP CGI affecting Windows systems when using certain locale settings. Allows remote code execution through crafted HTTP requests.
Year
2024
Type
CGI RCE
Impact
Critical
Repo
CVE-2024-4577
CRITICAL
CVE-2022-1388
CVSS 9.8
F5 BIG-IP iControl REST API Authentication Bypass
Critical authentication bypass vulnerability in F5 BIG-IP iControl REST API that allows unauthenticated remote code execution with administrative privileges.
Year
2022
Type
Auth Bypass
Impact
Critical
Stars
⭐ 5
CRITICAL
CVE-2025-29927
CVSS 9.1
Next.js Middleware Authorization Bypass
Authorization bypass vulnerability in Next.js middleware that allows attackers to access protected routes by manipulating request headers and bypassing security controls.
Year
2025
Type
Auth Bypass
Impact
Critical
Repo
CVE-2025-29927
HIGH
Ivanti_PoC
High Impact
Ivanti Endpoint Manager Mobile Authentication Bypass
Authentication bypass vulnerability in Ivanti Endpoint Manager Mobile (EPMM) that allows unauthorized access to administrative functions and sensitive enterprise data.
Year
2024
Type
Auth Bypass
Impact
High
Stars
⭐ 3
MEDIUM
CVE-2024-45440
CVSS 5.3
Drupal 11.x-dev Full Path Disclosure
Information disclosure vulnerability in Drupal 11.x-dev that exposes sensitive file system paths through the authorize.php endpoint. The vulnerability allows attackers to discover server directory structures, settings.php locations, and potentially sensitive configuration file paths without authentication.
Year
2024
Type
Info Disclosure
Impact
Medium
Target
Drupal
ARSENAL
3xplo1tz
Multi-CVE
Advanced Exploitation Collection
Comprehensive collection of 10 advanced proof-of-concept exploits including CVE-2025-31161, CVE-2024-4879, CVE-2024-28995, CVE-2024-0204, CVE-2023-30258, MS15-034, Shellshock, SpringBoot, TeamCity, and Zyxel PoC. Multi-platform exploitation toolkit for security research.
Exploits
10 PoCs
Type
Multi-Vector
Impact
Various
Collection
Research