PoC Archive PoC Archive

tag

Docker

Docker — CopyEscape: Container-to-Host Escape via docker cp Race Condition (CVE-2026-17106)
CVE-2026-17106 binary Unverified
CVE-2026-17106binaryCRITICAL 9.8Unverified2026-08-15MariaDB — Low-Privilege Remote Code Execution via ST_Area OOB Read + SYS_REFCURSOR Use-After-Free
MDEV-40328 (ST_Area OOB read); cursor-array UAF has no assigned CVE yet binary Unpatched
MDEV-40328binaryCRITICAL 8.8Unpatched2026-08-09Gitea Docker Image Reverse-Proxy Authentication Bypass — "One Header, Any User" (CVE-2026-20896)
CVE-2026-20896 (GHSA-f75j-4cw6-rmx4) web Patched
CVE-2026-20896webCRITICAL 9.8Patched2026-07-11Spring Cloud Gateway Actuator RCE — Vulnerable Environment Lab (CVE-2025-41243)
CVE-2025-41243 web Unpatched
CVE-2025-41243webCRITICAL 10Unpatched2026-07-06RediShell: Redis Lua Scripting Use-After-Free Leading to JOP-Chained Remote Code Execution (CVE-2025-49844) EPSS 87%
CVE-2025-49844 binary Patched
CVE-2025-49844binaryCRITICAL 9.9Patched2026-07-06Monsta FTP Pre-Authentication Remote Code Execution via Arbitrary File Upload (CVE-2025-34299) EPSS 73%
CVE-2025-34299 network Patched
CVE-2025-34299networkCRITICAL 9.8Patched2026-07-06IngressNightmare: Kubernetes ingress-nginx Admission Controller Shared-Library Injection RCE (CVE-2025-1974) EPSS 100%
CVE-2025-1974 cloud Unverified
CVE-2025-1974cloudCRITICAL 9.8Unverified2026-07-06Grafana Enterprise SCIM User ID Collision / Impersonation (CVE-2025-41115) EPSS 19%
CVE-2025-41115 web Patched
CVE-2025-41115webCRITICAL 10Patched2026-07-06OpenLearnX Unauthenticated RCE via Container Volume Mount (CVE-2026-41900)
CVE-2026-41900 (GHSA-8h25-q488-4hxw) cloud Patched
CVE-2026-41900cloudHIGH 8.6Patched2026-07-05Ollama GGUF Heap Out-of-Bounds Read During Quantization — CVE-2026-7482
CVE-2026-7482 misc Patched
CVE-2026-7482miscMEDIUMPatched2026-07-05Nginx QUIC/HTTP-3 DCID Length Heap Overflow Lab (CVE-2026-0211)
CVE-2026-0211 (repository explicitly labels this as a hypothetical/simulated CVE for coursework, not a confirmed vendor-assigned vulnerability) web Unverified
CVE-2026-0211webHIGHUnverified2026-07-05MLflow / MLServer Insecure Pickle Deserialization RCE — CVE-2026-0596
CVE-2026-0596 (GHSA-rvhj-8chj-8v3c) web Unverified
CVE-2026-0596webCRITICAL 9.6Unverified2026-07-05MikroORM Custom Type Raw SQL Injection (CVE-2026-34220)
CVE-2026-34220 web Patched
CVE-2026-34220webHIGHPatched2026-07-05LiteLLM Guardrail Custom-Code Sandbox Escape to Root RCE (CVE-2026-40217) EPSS 15%
CVE-2026-40217 (X41-2026-001, GHSA-3926-2jvf-fg29) web Patched
CVE-2026-40217webCRITICAL 8.8Patched2026-07-05Fireshare Unauthenticated Arbitrary File Write/Overwrite — CVE-2026-54337
CVE-2026-54337 (see [GHSA-hmh2-6g84-q8jx](https://github.com/ShaneIsrael/fireshare/security/advisories/GHSA-hmh2-6g84-q8jx)) web Unverified
CVE-2026-54337webINFOUnverified2026-07-05Coolify Authenticated Remote Command Injection via Deployment Config (CVE-2026-34038)
CVE-2026-34038 (GHSA-qqrq-r9h4-x6wp) web Patched
CVE-2026-34038webCRITICAL 10Patched2026-07-05Gitea act_runner container.options Host Namespace Escape
None assigned as of 2026-07-03 cloud Unverified
None assigned as of 2026-07-03cloudHIGHUnverified2026-07-03Docker cp Copy-Out Destination Escape via Symlink Race
None assigned as of 2026-07-03 cloud Unverified
None assigned as of 2026-07-03cloudMEDIUMUnverified2026-07-03