PoC Archive PoC Archive

tag

Cwe-321

Critical
Flowise Enterprise Authentication Bypass via Hardcoded Default JWT Secrets (CVE-2026-56271)
CVE-2026-56271 (GHSA-cc4f-hjpj-g9p8)· Flowise — open-source low-code LLM/agent orchestration platform (enterprise edition, passport authentication middleware) patched
Critical
Gladinet CentreStack / Triofox Hardcoded AES Key Access-Ticket Forgery to Arbitrary File Read (CVE-2025-14611)
CVE-2025-14611· Gladinet CentreStack and Triofox (GladCtrl64.dll / filesvr.dn file-download handler) unpatched
High
Lansweeper lsrunase 2.0 / lsencrypt 2.0 — RC4 Password Recovery (CVE-2026-39031)
CVE-2026-39031· Lansweeper lsrunase 2.0 / lsencrypt 2.0 unpatched
Critical
HAXcms Node.js Private Key Disclosure via Broken HMAC (CVE-2026-46395)
CVE-2026-46395· HAXcms Node.js backend (elmsln/HAXcms, haxcms-nodejs) — src/lib/HAXCMS.js patched