PoC Archive PoC Archive

tag

Cwe-639

Apache Polaris — Cross-Tenant Credential Vending Before Location Validation in Iceberg REST Register (CVE-2026-64640)
CVE-2026-64640 cloud Patched
CVE-2026-64640cloudHIGH 8.1Patched2026-08-09Langflow Responses API IDOR — Execute Another User's Flow (CVE-2026-55255) KEV
CVE-2026-55255 (GHSA-qrpv-q767-xqq2) web Patched
CVE-2026-55255webHIGH 8.4Patched2026-07-19WordPress Service Finder Bookings ≤ 6.0 Authentication Bypass via `original_user_id` Cookie (CVE-2025-5947)
CVE-2025-5947 web Unverified
CVE-2025-5947webCRITICAL 9.8Unverified2026-07-06Saleor GraphQL IDOR — Unauthenticated Order PII Exfiltration (CVE-2026-24136)
CVE-2026-24136 web Patched
CVE-2026-24136webHIGH 7.5Patched2026-07-05