PoC Archive PoC Archive

Proof-of-concept research filed under the misc category.

Entries

33

in misc

CISA KEV

3

exploited in the wild

Ransomware

1

known campaign use

Unpatched

7

no vendor fix

Critical

8

24% of listed

33 entries

Severity

Exploitation signals

Patch status

Date range

→
Sort

33 result(s)

MISC LIST 33 shown · 33 indexed
PoC titleSeverity
Ghidra — Swift Demangler Arbitrary Code Execution via Shared Project Files (CVE-2026-18718)
CVE-2026-18718 misc Patched
HIGH 7.5
safe-expr-eval: Mitigation Library for the expr-eval Unsafe eval() RCE (CVE-2025-12735)
CVE-2025-12735 misc Patched
CRITICAL 9.8
Python tarfile `filter="data"` Bypass via PATH_MAX/realpath Confusion (CVE-2025-4517)
CVE-2025-4517 misc Patched
CRITICAL 9.4
Apache Parquet-Avro Schema Deserialization RCE/SSRF — Incomplete-Fix Bypass (CVE-2025-30065) EPSS 43%
CVE-2025-30065 misc Patched
CRITICAL 9.8
UnPoller Path Traversal / Arbitrary File Read via file:// Password Prefix (CVE-2026-36851)
CVE-2026-36851 misc Unverified
HIGH 7.5
Rapid7 Nexpose Weak Keystore Entropy Credential Decryption — CVE-2026-1814
CVE-2026-1814 misc Unverified
HIGH
pypdf Circular Outline Reference Infinite-Loop DoS (CVE-2026-24688)
CVE-2026-24688 misc Patched
HIGH
psf/black GitHub Action RCE via Insecure Regex Version Validation — CVE-2026-31900
CVE-2026-31900 (GHSA-v53h-f6m7-xcgm) misc Patched
HIGH 8.7
Orval OpenAPI Codegen Arbitrary Code Execution via Malicious Spec (CVE-2026-23947)
CVE-2026-23947 misc Patched
HIGH
Ollama GGUF Heap Out-of-Bounds Read During Quantization — CVE-2026-7482
CVE-2026-7482 misc Patched
MEDIUM
npm `tar` Package Unicode-Normalization Race Condition / File Collision (CVE-2026-2395)
CVE-2026-2395 misc Unverified
MEDIUM
Node.js `tar` Package Symlink Path Traversal — CVE-2026-29786
CVE-2026-29786 misc Patched
HIGH
node-tar Hardlink/Symlink Path Traversal Arbitrary File Overwrite (CVE-2026-23745)
CVE-2026-23745 / GHSA-8qq5-rm4j-mr97 misc Patched
HIGH
Netflix Conductor Unauthenticated RCE via INLINE GraalVM Evaluator — CVE-2026-58138
CVE-2026-58138 ([VulnCheck advisory](https://www.vulncheck.com/advisories/orkes-conductor-unauthenticated-rce-via-graalvm-script-evaluators)) misc Patched
CRITICAL 9.8
Multiparty Denial of Service via Prototype-Pollution Field Name (CVE-2026-8161)
CVE-2026-8161 / GHSA-qxch-whhj-8956 misc Patched
MEDIUM
Microsoft Semantic Kernel In-Memory Vector Store Filter eval() Sandbox Bypass RCE (CVE-2026-26030)
CVE-2026-26030 misc Patched
CRITICAL
Malicious DOCX/OLE CLSID Object Embedding Builder (CVE-2026-21509) KEV EPSS 73%
CVE-2026-21509 misc Unverified
HIGH
local-mcp exec Tool Sandbox/Restriction Bypass (CVE-2026-6130)
CVE-2026-6130 misc Unverified
MEDIUM
LiquidJS Template Engine Path Traversal — CVE-2026-30952
CVE-2026-30952 (GHSA-wmfp-5q7x-987x) misc Patched
HIGH 8.7
iOS App Intents Path Traversal — CVE-2026-28995
CVE-2026-28995 misc Patched
HIGH
Feast Registry gRPC Unauthenticated RCE via dill.loads — CVE-2026-56121
CVE-2026-56121 misc Patched
CRITICAL 9.8
exiftool-vendored.js Argument Injection via Newline-Delimited Tag Names (CVE-2026-43893)
CVE-2026-43893 / GHSA-cw26-7653-2rp5 misc Patched
HIGH 8.2
docling-core Unsafe YAML Deserialization Leading to Code Execution — CVE-2026-24009
CVE-2026-24009 misc Patched
HIGH
Claude Code WebFetch Hardcoded HuggingFace Bare-Hostname Allow-List Bypass — CVE-2026-54316
CVE-2026-54316 (GHSA-fg94-h982-f3mm) misc Patched
MEDIUM
ChatterBot Denial of Service via SQLAlchemy Connection Pool Exhaustion (CVE-2026-23842)
CVE-2026-23842 misc Patched
HIGH 7.5
Apktool Resource Table Path Traversal — Malicious APK Builder (CVE-2026-39973)
CVE-2026-39973 misc Patched
HIGH
AI Model-Loader `trust_remote_code` Order-of-Operations RCE Simulation (CVE-2026-22807)
CVE-2026-22807 misc Patched
HIGH
Adobe Acrobat/Reader PDF Exploit Generator — Claimed Prototype Pollution (CVE-2026-3462)
CVE-2026-3462 (repo internally references CVE-2026-34621 — CVE-ID mismatch, see Notes) misc Patched
CRITICAL
7-Zip RAR5 Mark-of-the-Web / ADS Full-Chain Bypass
None assigned as of 2026-07-03 misc Unverified
HIGH
WinRAR Windows Path Traversal via NTFS Alternate Data Streams (CVE-2025-8088) KEV RW EPSS 95%
CVE-2025-8088 misc Patched
HIGH 8.4
YellowKey — BitLocker Bypass via WinRE autofstx.exe (CVE-2026-45585)
CVE-2026-45585 misc Patched
MEDIUM 6.1
Apache Parquet Java Unsafe Deserialization RCE (CVE-2025-30065) EPSS 43%
CVE-2025-30065 misc Patched
CRITICAL 10
WinRAR Archive Extraction Path Traversal (CVE-2025-6218) KEV EPSS 90%
CVE-2025-6218 misc Unverified
HIGH