PoC Archive PoC Archive

tag

Docker-Lab

Critical
Spring AI SimpleVectorStore SpEL Injection RCE (CVE-2026-22738)
CVE-2026-22738· Spring AI spring-ai-core (SimpleVectorStore) patched
Critical
Spinnaker Clouddriver — Git Clone Shell Injection RCE (CVE-2026-32604)
CVE-2026-32604 (CWE-78)· Spinnaker (Clouddriver service) — continuous delivery / multi-cloud orchestration platform unpatched
Critical
rclone RC API Unauthenticated Remote Code Execution (CVE-2026-41179)
CVE-2026-41179· rclone (Remote Control / rcd HTTP API) patched
Critical
OWASP CoreRuleSet Multipart Charset WAF Bypass (CVE-2026-21876)
CVE-2026-21876· unpatched
Medium
nginx Resolver Use-After-Free in OCSP Stapling (CVE-2026-40701)
CVE-2026-40701· nginx (open source) patched
High
NGINX HTTP/2 Frame Injection via Vulnerable Upstream Proxying (CVE-2026-42926)
CVE-2026-42926· NGINX (HTTP/2 upstream proxying) patched
Critical
MariaDB JSON_SCHEMA_VALID() Heap Overflow — Privilege Escalation to UDF RCE (CVE-2026-32710)
CVE-2026-32710· MariaDB (JSON_SCHEMA_VALID() SQL function) unpatched
High
Langflow Knowledge Base Path Traversal / Arbitrary Directory Deletion (CVE-2026-42048)
CVE-2026-42048 (GHSA-9whx-c884-c68q)· Langflow (Knowledge Bases bulk delete API) patched
High (advisory also describes user impersonation and Script Console RCE via the same primitive; this PoC demonstrates file-read impact only)
Jenkins ClassFilter Deserialization Bypass → Arbitrary File Read — CVE-2026-53435
CVE-2026-53435 (Jenkins SECURITY-3707)· Jenkins (core), View configuration (config.xml) deserialization path patched
Critical
Ivanti EPMM Pre-Auth RCE via Bash Arithmetic Expansion (CVE-2026-1281 / CVE-2026-1340)
CVE-2026-1281, CVE-2026-1340· Ivanti Endpoint Manager Mobile (EPMM), map-appstore-url CGI handler unpatched
Critical
Gotenberg 8.29.1 Unauthenticated ExifTool Metadata Key Injection RCE (CVE-2026-42589)
CVE-2026-42589· Gotenberg (document/PDF conversion microservice) patched
Medium
Claude Code WebFetch Hardcoded HuggingFace Bare-Hostname Allow-List Bypass — CVE-2026-54316
CVE-2026-54316 (GHSA-fg94-h982-f3mm)· @anthropic-ai/claude-code (npm package, Claude Code CLI) patched
High
Business Directory Plugin for WordPress — Unauthenticated Time-Based Blind SQL Injection (CVE-2026-2576)
CVE-2026-2576· Business Directory Plugin (Easy Listing Directories) for WordPress patched
Critical
Apache Tomcat Mutual TLS OCSP Soft-Fail Authentication Bypass — CVE-2026-29145
CVE-2026-29145· Apache Tomcat (CLIENT_CERT / Mutual TLS authentication) unpatched