PoC Archive PoC Archive

tag

Data-Exfiltration

WordPress "Form Maker" Plugin Unauthenticated SQL Injection — CVE-2026-3359
CVE-2026-3359 web Unverified
CVE-2026-3359webCRITICALUnverified2026-07-05Sliver C2 MCP Server Unauthenticated CORS/Preflight Bypass (CVE-2026-34227)
CVE-2026-34227 (GHSA-6fpf-248c-m7wm) web Unverified
CVE-2026-34227webHIGHUnverified2026-07-05pdfmake Server-Side Request Forgery via Unvalidated Document URLs (CVE-2026-26801)
CVE-2026-26801 web Patched
CVE-2026-26801webHIGHPatched2026-07-05adx-mcp-server KQL Injection via table_name Parameter (CVE-2026-33980)
CVE-2026-33980 web Patched
CVE-2026-33980webHIGH 8.8Patched2026-07-05Drupal Core PostgreSQL SQL Injection (CVE-2026-9082) KEV EPSS 88%
CVE-2026-9082 / SA-CORE-2026-004 web Patched
CVE-2026-9082 / SA-CORE-2026-004webCRITICALPatched2026-05-30