PoC Archive PoC Archive

tag

Cwe-943

Mongoose `populate()` Match `$where` Bypass Command Injection (CVE-2025-23061)
CVE-2025-23061 web Patched
CVE-2025-23061webCRITICAL 9Patched2026-07-06graphiti-core Cypher Injection via Unsanitized node_labels — CVE-2026-32247
CVE-2026-32247 (GHSA, getzep/graphiti) web Patched
CVE-2026-32247webHIGH 8.1Patched2026-07-05adx-mcp-server KQL Injection via table_name Parameter (CVE-2026-33980)
CVE-2026-33980 web Patched
CVE-2026-33980webHIGH 8.8Patched2026-07-05