PoC Archive PoC Archive

tag

Express

Mongoose `populate()` Match `$where` Bypass Command Injection (CVE-2025-23061)
CVE-2025-23061 web Patched
CVE-2025-23061webCRITICAL 9Patched2026-07-06Sequelize ORM JSON Cast SQL Injection — CVE-2026-30951
CVE-2026-30951 web Patched
CVE-2026-30951webHIGHPatched2026-07-05Node.js protobufjs Dynamic Type Compilation RCE (CVE-2026-41242)
CVE-2026-41242 web Patched
CVE-2026-41242webCRITICALPatched2026-07-05Multer Orphaned Temporary File Disk-Exhaustion DoS — CVE-2026-3304
CVE-2026-3304 web Patched
CVE-2026-3304webHIGH 8.7Patched2026-07-05Handlebars AST Injection Remote Code Execution — CVE-2026-33937
CVE-2026-33937 web Patched
CVE-2026-33937webCRITICALPatched2026-07-05