g0vguy

3 exploits Active since Oct 2025
CVE-2025-61922 NOMISEC CRITICAL WORKING POC
PrestaShop Checkout 1.3.0-4.4.0 and 5.0.0-5.0.4 - Account Takeover via Express Checkout Email Validation Bypass
PrestaShop Checkout is the PrestaShop official payment module in partnership with PayPal. Starting in version 1.3.0 and prior to versions 4.4.1 and 5.0.5, missing validation on the Express Checkout feature allows silent login, enabling account takeover via email. The vulnerability is fixed in versions 4.4.1 and 5.0.5. No known workarounds exist.
8 stars
CVSS 9.1
CVE-2025-37164 NOMISEC CRITICAL WORKING POC
HPE OneView unauthenticated RCE
A remote code execution issue exists in HPE OneView.
6 stars
CVSS 10.0
CVE-2026-23760 NOMISEC CRITICAL WORKING POC
SmarterTools SmarterMail <9511 - Auth Bypass
SmarterTools SmarterMail versions prior to build 9511 contain an authentication bypass vulnerability in the password reset API. The force-reset-password endpoint permits anonymous requests and fails to verify the existing password or a reset token when resetting system administrator accounts. An unauthenticated attacker can supply a target administrator username and a new password to reset the account, resulting in full administrative compromise of the SmarterMail instance. NOTE: SmarterMail system administrator privileges grant the ability to execute operating system commands via built-in management functionality, effectively providing administrative (SYSTEM or root) access on the underlying host.
CVSS 9.8