PoC Archive PoC Archive

tag

Cwe-943

Critical
Mongoose `populate()` Match `$where` Bypass Command Injection (CVE-2025-23061)
CVE-2025-23061· Mongoose (Node.js MongoDB ODM) unpatched
High
graphiti-core Cypher Injection via Unsanitized node_labels — CVE-2026-32247
CVE-2026-32247 (GHSA, getzep/graphiti)· graphiti-core (getzep/graphiti) — memory/graph layer used by AI agent frameworks, exposed via an MCP server patched
High
adx-mcp-server KQL Injection via table_name Parameter (CVE-2026-33980)
CVE-2026-33980· adx-mcp-server (pab1it0/adx-mcp-server) unpatched