PoC Archive PoC Archive

tag

Credential-Theft

LiteLLM Proxy Pre-Authentication SQL Injection via Error-Handling Callback (CVE-2026-42208) KEV EPSS 89%
CVE-2026-42208 (GHSA-r75f-5x8p-qvmc) web Patched
CVE-2026-42208webCRITICAL 9.8Patched2026-07-11TNC Toolbox: Web Performance Unauthenticated cPanel Credential Exposure (CVE-2025-12539)
CVE-2025-12539 web Patched
CVE-2025-12539webCRITICAL 10Patched2026-07-06RustFS Hardcoded gRPC Authentication Token Leading to Full Node Compromise (CVE-2025-68926) EPSS 31%
CVE-2025-68926 cloud Patched
CVE-2025-68926cloudCRITICAL 9.8Patched2026-07-06pdfmake Server-Side Request Forgery via Unvalidated Document URLs (CVE-2026-26801)
CVE-2026-26801 web Patched
CVE-2026-26801webHIGHPatched2026-07-05OpenSTAManager Scadenzario Bulk Operations Error-Based SQL Injection — CVE-2026-24418
CVE-2026-24418 web Patched
CVE-2026-24418webHIGH 8.8Patched2026-07-05OpenSTAManager Prima Nota Error-Based SQL Injection — CVE-2026-24419
CVE-2026-24419 web Patched
CVE-2026-24419webHIGHPatched2026-07-05OpenSTAManager Article Pricing Time-Based Blind SQL Injection — CVE-2026-24416
CVE-2026-24416 web Patched
CVE-2026-24416webHIGHPatched2026-07-05Nhost Local MCP Server Unauthenticated CORS Bypass Leading to Full Project Takeover (CVE-2026-34200)
CVE-2026-34200 (GHSA-6c5x-3h35-vvw2) web Patched
CVE-2026-34200webCRITICAL 9.6Patched2026-07-05Fortinet FortiClient EMS Pre-Auth Bypass — "FortiBleed" (CVE-2026-35616) KEV EPSS 91%
CVE-2026-35616 network Patched
CVE-2026-35616networkCRITICAL 9.1Patched2026-07-03Squidbleed — Squid Proxy FTP Gateway Out-of-Bounds Heap Read (CVE-2026-47729)
CVE-2026-47729 network Patched
CVE-2026-47729networkMEDIUMPatched2026-07-01Windows NTLM Hash Disclosure via File Explorer - CVE-2025-24054 KEV EPSS 59%
CVE-2025-24054 binary Unverified
CVE-2025-24054binaryMEDIUM 6.5Unverified2026-05-17Jenkins CLI Arbitrary File Read to RCE (CVE-2024-23897) KEV RW EPSS 100%
CVE-2024-23897 web Patched
CVE-2024-23897webCRITICAL 9.8Patched2026-05-17