PoC Archive PoC Archive

tag

JavaScript

React Router Session Path Traversal (CVE-2025-61686)
CVE-2025-61686 web Unverified
CVE-2025-61686webCRITICAL 9.1Unverified2026-09-03Node.js Permission Model Symlink Escape (CVE-2025-55130)
CVE-2025-55130 binary Unverified
CVE-2025-55130binaryCRITICAL 9.1Unverified2026-09-03Firefox SpiderMonkey JIT Type Confusion (CVE-2026-10702)
CVE-2026-10702 binary Unverified
CVE-2026-10702binaryMEDIUM 4.3Unverified2026-09-03Chrome V8 Type Confusion RCE (CVE-2026-5865)
CVE-2026-5865 binary Unverified
CVE-2026-5865binaryHIGH 8.8Unverified2026-09-03safe-expr-eval: Mitigation Library for the expr-eval Unsafe eval() RCE (CVE-2025-12735)
CVE-2025-12735 misc Patched
CVE-2025-12735miscCRITICAL 9.8Patched2026-07-06WebKit Navigation API Cross-Port canIntercept Bypass (CVE-2026-20643)
CVE-2026-20643 web Unverified
CVE-2026-20643webMEDIUMUnverified2026-07-05TanStack Query — Unbounded Recursion Denial of Service in `replaceEqualDeep` (CVE-2026-26903)
CVE-2026-26903 web Patched
CVE-2026-26903webMEDIUMPatched2026-07-05Saleor Stored XSS via Unrestricted File Upload (CVE-2026-23499)
CVE-2026-23499 web Patched
CVE-2026-23499webHIGHPatched2026-07-05Realtime Collaboration Platform — CORS Misconfiguration Leading to Authenticated Data Exposure (CVE-2026-27579)
CVE-2026-27579 (GHSA-qh5m-p8jh-hx88) web Unverified
CVE-2026-27579webHIGH 7.4Unverified2026-07-05oRPC OpenAPI Reference Plugin Stored XSS via Unescaped Spec Embedding (CVE-2026-33331)
CVE-2026-33331 (GHSA-7f6v-3gx7-27q8) web Patched
CVE-2026-33331webHIGHPatched2026-07-05Node.js protobufjs Dynamic Type Compilation RCE (CVE-2026-41242)
CVE-2026-41242 web Patched
CVE-2026-41242webCRITICALPatched2026-07-05Math.js Expression Parser Sandbox Bypass RCE (CVE-2026-40897)
CVE-2026-40897 web Patched
CVE-2026-40897webCRITICALPatched2026-07-05Next.js unstable_cache Object-Argument Cache-Key Collision
None assigned as of 2026-07-03 web Unverified
None assigned as of 2026-07-03webHIGHUnverified2026-07-03Google Chromium V8 Out-of-Bounds Read/Write — Crash PoC (CVE-2026-11645) KEV
CVE-2026-11645 web Unverified
CVE-2026-11645webHIGH 8.8Unverified2026-07-01Confluence Post-Auth RCE - CVE-2024-21683 EPSS 88%
CVE-2024-21683 web Unverified
CVE-2024-21683webHIGH 8.3Unverified2026-05-17