PoC Archive PoC Archive

tag

Javascript-Injection

Critical
Flowise CustomMCP Unauthenticated Remote Code Execution via Function() Constructor (CVE-2025-59528)
CVE-2025-59528· Flowise (FlowiseAI/Flowise) patched
Critical
OpenRemote — Expression Injection RCE in Rules Engine (CVE-2026-39842)
CVE-2026-39842 / GHSA-7mqr-33rv-p3mp· OpenRemote (IoT device/rules management platform) patched
Critical
DbGate Unauthenticated RCE via JSON Script Runner (CVE-2026-47668)
CVE-2026-47668· DbGate (dbgate-serve — web-based database management tool) patched