PoC Archive PoC Archive

tag

Curl

  • CVE-2026-20200 / NSIDE-SA-2026-003 network CRITICAL 9.9

    Cisco IMC Argument Injection to Root RCE (CVE-2026-20200)

    CVE-2026-20200 is an argument injection vulnerability in Cisco IMC that allows an authenticated user to achieve root-level RCE. The Redfish API SSH key upload handler (ManagerAccount.UploadSSHKey) passes the KeyURI parameter to curl without sanitization. An…

    Patched 2026-08-16
  • CVE-2025-65856 hardware CRITICAL 9.8

    Xiongmai XM530 IP Camera ONVIF Authentication Bypass (CVE-2025-65856)

    CVE-2025-65856 is a critical authentication bypass in the ONVIF implementation shipped on Xiongmai XM530-based IP cameras. The device's deviceservice and mediaservice ONVIF SOAP endpoints accept and fully process requests such as GetDeviceInformation,…

    Unverified 2026-07-06
  • CVE-2026-23744 web CRITICAL EPSS 45%

    MCPJam Inspector Unauthenticated Command Injection RCE (CVE-2026-23744)

    This repository is a German-language Hack The Box "DevHub" walkthrough that documents a full attack chain, one step of which is a genuine, directly reusable RCE against MCPJam Inspector v1.4.2 (CVE-2026-23744). The vulnerable /api/mcp/connect endpoint accepts…

    Patched 2026-07-05
  • CVE-2026-33017 web CRITICAL KEV EPSS 100%

    Langflow Custom Component Remote Code Execution — CVE-2026-33017

    Langflow exposes a REST API endpoint that builds and runs a "flow" — a graph of nodes describing a data/LLM pipeline. One of the supported node types is a generic custom component whose code field is arbitrary Python that Langflow imports and executes…

    Patched 2026-07-05
  • CVE-2026-3805 network HIGH

    curl SMB Connection-Reuse Use-After-Free (CVE-2026-3805)

    libcurl's SMB protocol handler stores a request-scoped req->path pointer that points into memory owned by a temporary "needle" connection object used during connection-cache lookup (smbc->share). When a second SMB transfer to the same server reuses an…

    Patched 2026-07-05
  • None assigned as of 2026-07-03 network MEDIUM

    curl SMTP EXPN Recipient CRLF Command Injection

    Stock curl does not reject CR/LF sequences in the recipient operand used with SMTP EXPN/VRFY custom requests (CURLOPTMAILRCPT), allowing an attacker who controls that operand to inject arbitrary additional SMTP protocol lines into the same authenticated…

    Unverified 2026-07-03