PoC Archive PoC Archive

tag

Information-Disclosure

Apache Polaris — Cross-Tenant Credential Vending Before Location Validation in Iceberg REST Register (CVE-2026-64640)
CVE-2026-64640 cloud Patched
CVE-2026-64640cloudHIGH 8.1Patched2026-08-09Xiongmai XM530 IP Camera ONVIF Authentication Bypass (CVE-2025-65856)
CVE-2025-65856 hardware Unverified
CVE-2025-65856hardwareCRITICAL 9.8Unverified2026-07-06Twonky Server 8.5.2 Unauthenticated `/nmc/rpc/` Auth Bypass & Admin Credential Log Leak (CVE-2025-13315) EPSS 33%
CVE-2025-13315 network Unpatched
CVE-2025-13315networkCRITICAL 9.8Unpatched2026-07-06Squid Proxy Sensitive Header Leak via Error Page `mailto:` Diagnostic Block (CVE-2025-62168) EPSS 63%
CVE-2025-62168 network Patched
CVE-2025-62168networkCRITICAL 10Patched2026-07-06RustFS Hardcoded gRPC Authentication Token Leading to Full Node Compromise (CVE-2025-68926) EPSS 31%
CVE-2025-68926 cloud Patched
CVE-2025-68926cloudCRITICAL 9.8Patched2026-07-06Pterodactyl Panel Unauthenticated Path Traversal via locale.json Leaking Database Credentials (CVE-2025-49132) EPSS 53%
CVE-2025-49132 web Patched
CVE-2025-49132webCRITICAL 10Patched2026-07-06AI Engine WordPress Plugin Unauthenticated MCP Token Disclosure to Admin Account Creation (CVE-2025-11749) EPSS 75%
CVE-2025-11749 web Unverified
CVE-2025-11749webCRITICAL 9.8Unverified2026-07-06ZTE ZXHN H298A / H108N Router Unauthenticated Credential Disclosure (CVE-2026-34474) EPSS 25%
CVE-2026-34474 network Unverified
CVE-2026-34474networkHIGHUnverified2026-07-05Xboard / V2Board — Magic Link Token Leak Unauth Account Takeover (CVE-2026-39912)
CVE-2026-39912 web Patched
CVE-2026-39912webCRITICAL 9.1Patched2026-07-05WebKit WebGPU `importExternalTexture` Cross-Origin Video Frame Leak (CVE-2026-43700)
CVE-2026-43700 web Unverified
CVE-2026-43700webHIGHUnverified2026-07-05WebKit Navigation API `NavigateEvent.sourceElement` Cross-Origin DOM Leak (CVE-2026-43735)
CVE-2026-43735 web Unverified
CVE-2026-43735webHIGHUnverified2026-07-05Veno File Manager Absolute Path Disclosure (CVE-2026-37069)
CVE-2026-37069 web Unverified
CVE-2026-37069webLOWUnverified2026-07-05phpSysInfo IP Allowlist Bypass via X-Forwarded-For Spoofing — CVE-2026-55584
CVE-2026-55584 / GHSA-786w-p5pm-cvgh web Patched
CVE-2026-55584 / GHSA-786w-p5pm-cvghwebHIGH 7.5Patched2026-07-05Notepad++ nativeLang.xml Format String Crash / Info Disclosure — CVE-2026-3008
CVE-2026-3008 binary Unverified
CVE-2026-3008binaryMEDIUMUnverified2026-07-05InvoicePlane Unauthenticated Path Traversal in Guest Controller (CVE-2026-23491)
CVE-2026-23491 web Patched
CVE-2026-23491webCRITICALPatched2026-07-05GitLab WebSocket GraphqlChannel Unauthorized Method Enumeration — CVE-2026-5173
CVE-2026-5173 web Patched
CVE-2026-5173webHIGHPatched2026-07-05Gitea Container Registry Anonymous Auth Bypass (CVE-2026-27771)
CVE-2026-27771 web Patched
CVE-2026-27771webCRITICALPatched2026-07-05Apache HTTP Server mod_rewrite/mod_setenvif/mod_proxy_fcgi ap_expr Local File Read — CVE-2026-24072
CVE-2026-24072 web Patched
CVE-2026-24072webMEDIUMPatched2026-07-05Android ActivityManagerService dumpBitmapsProto() Missing Permission Check (CVE-2026-0047)
CVE-2026-0047 binary Unpatched
CVE-2026-0047binaryCRITICAL 8.4Unpatched2026-07-05Next.js unstable_cache Object-Argument Cache-Key Collision
None assigned as of 2026-07-03 web Unverified
None assigned as of 2026-07-03webHIGHUnverified2026-07-03Firefox Smart Window Private URL Exfiltration
None assigned as of 2026-07-03 web Unverified
None assigned as of 2026-07-03webHIGHUnverified2026-07-03Squidbleed — Squid Proxy FTP Gateway Out-of-Bounds Heap Read (CVE-2026-47729)
CVE-2026-47729 network Patched
CVE-2026-47729networkMEDIUMPatched2026-07-01Next.js i18n Middleware Bypass (CVE-2026-44573)
CVE-2026-44573 web Patched
CVE-2026-44573webHIGH 7.5Patched2026-05-17