PoC Archive PoC Archive

Proof-of-concept research filed under the cloud category.

Entries

21

in cloud

CISA KEV

0

exploited in the wild

Ransomware

0

known campaign use

Unpatched

7

no vendor fix

Critical

9

43% of listed

21 entries

Severity

Exploitation signals

Patch status

Date range

→
Sort

21 result(s)

CLOUD LIST 21 shown · 21 indexed
PoC titleSeverity
Apache Polaris — Cross-Tenant Credential Vending Before Location Validation in Iceberg REST Register (CVE-2026-64640)
CVE-2026-64640 cloud Patched
HIGH 8.1
tj-actions/branch-names GitHub Actions Command Injection (CVE-2025-54416)
CVE-2025-54416 cloud Patched
CRITICAL 9.1
RustFS Hardcoded gRPC Authentication Token Leading to Full Node Compromise (CVE-2025-68926) EPSS 31%
CVE-2025-68926 cloud Patched
CRITICAL 9.8
IngressNightmare: Kubernetes ingress-nginx Admission Controller Shared-Library Injection RCE (CVE-2025-1974) EPSS 100%
CVE-2025-1974 cloud Unverified
CRITICAL 9.8
Supply Chain Command Injection in AWS CDK's NodejsFunction — CVE-2026-11417
CVE-2026-11417 cloud Patched
HIGH 3.1
Spinnaker Clouddriver — Git Clone Shell Injection RCE (CVE-2026-32604)
CVE-2026-32604 (CWE-78) cloud Patched
CRITICAL 10
Sherlock CI `pull_request_target` Command Injection → GitHub Actions Secret Exfiltration (CVE-2026-44590)
CVE-2026-44590 cloud Patched
CRITICAL 9.3
RustFS — Presigned POST Policy Condition Bypass (CVE-2026-27607)
CVE-2026-27607 (GHSA-w5fh-f8xh-5x3p) cloud Patched
HIGH
Plunk SSRF via Unvalidated AWS SNS SubscriptionConfirmation — CVE-2026-32096
CVE-2026-32096 cloud Patched
CRITICAL 9.3
OS Command Injection in KubeAI via Model URL (CVE-2026-34940)
CVE-2026-34940 cloud Patched
HIGH 8.7
OpenLearnX Unauthenticated RCE via Container Volume Mount (CVE-2026-41900)
CVE-2026-41900 (GHSA-8h25-q488-4hxw) cloud Patched
HIGH 8.6
Kubernetes `runAsNonRoot` Bypass via UID Integer Overflow (CVE-2026-46680)
CVE-2026-46680 cloud Patched
HIGH
HashiCorp go-getter Git Pathspec Arbitrary File Read (CVE-2026-4660)
CVE-2026-4660 / HCSEC-2026-04 cloud Patched
HIGH 7.5
Apache Flink Kubernetes Operator SSRF via jarURI (CVE-2026-40564)
CVE-2026-40564 cloud Patched
HIGH
Amazon WorkSpaces Skylight Workspace Config Service Local Privilege Escalation (CVE-2026-7791)
CVE-2026-7791 cloud Unverified
HIGH
Nextcloud Federated Share OCM Bearer Token Scope Escalation to Sender WebDAV Access
None assigned as of 2026-07-03 cloud Unverified
HIGH
Gitea act_runner container.options Host Namespace Escape
None assigned as of 2026-07-03 cloud Unverified
HIGH
Floci API Gateway VTL RCE + IAM Scope Bypass
None assigned as of 2026-07-03 cloud Unverified
CRITICAL
Docker cp Copy-Out Destination Escape via Symlink Race
None assigned as of 2026-07-03 cloud Unverified
MEDIUM
IngressNightmare - Kubernetes Ingress-NGINX Unauthenticated RCE EPSS 100%
CVE-2025-1974 (primary); also CVE-2025-1097, CVE-2025-1098, CVE-2025-24514 cloud Unverified
CRITICAL 9.8
Azure Networking Privilege Escalation via Missing Privilege Check
CVE-2025-54914 cloud Patched
CRITICAL 10