PoC Archive PoC Archive

tag

Insecure-Deserialization

  • CVE-2026-0596 web CRITICAL 9.6

    MLflow / MLServer Insecure Pickle Deserialization RCE — CVE-2026-0596

    MLflow can serve models through Seldon's MLServer runtime, which loads model artifacts using Python's native pickle format. While the REST API's string parameters are handled safely and are not vulnerable to classic OS command injection, the underlying…

    Unverified 2026-07-05
  • CVE-2026-45247 web CRITICAL 9.3 KEV EPSS 28%

    Unauthenticated RCE in Mirasvit Full Page Cache Warmer for Magento 2 (CVE-2026-45247)

    CVE-2026-45247 is a PHP object injection / insecure deserialization vulnerability in Mirasvit's Full Page Cache Warmer extension for Magento 2. The extension processes attacker-controlled data from the CacheWarmer cookie and passes it directly to PHP's native…

    Unverified 2026-07-01