PoC Archive PoC Archive

tag

Mcp

AI Engine WordPress Plugin Unauthenticated MCP Token Disclosure to Admin Account Creation (CVE-2025-11749) EPSS 75%
CVE-2025-11749 web Unverified
CVE-2025-11749webCRITICAL 9.8Unverified2026-07-06Sliver C2 MCP Server Unauthenticated CORS/Preflight Bypass (CVE-2026-34227)
CVE-2026-34227 (GHSA-6fpf-248c-m7wm) web Unverified
CVE-2026-34227webHIGHUnverified2026-07-05Nhost Local MCP Server Unauthenticated CORS Bypass Leading to Full Project Takeover (CVE-2026-34200)
CVE-2026-34200 (GHSA-6c5x-3h35-vvw2) web Patched
CVE-2026-34200webCRITICAL 9.6Patched2026-07-05MCPJam Inspector Unauthenticated Command Injection RCE (CVE-2026-23744) EPSS 45%
CVE-2026-23744 web Patched
CVE-2026-23744webCRITICALPatched2026-07-05MCPJam Inspector / Arcane MCP Connect Command Injection RCE via Host-Header Vhost Routing (CVE-2026-23520)
CVE-2026-23520 web Patched
CVE-2026-23520webCRITICALPatched2026-07-05mcp-atlassian Path Traversal via confluence_upload_attachment (CVE-2026-27825) EPSS 13%
CVE-2026-27825 (read-side twin of GHSA-xjgw-4wvw-rgm4) web Patched
CVE-2026-27825webCRITICAL 9.3Patched2026-07-05local-mcp exec Tool Sandbox/Restriction Bypass (CVE-2026-6130)
CVE-2026-6130 misc Unverified
CVE-2026-6130miscMEDIUMUnverified2026-07-05graphiti-core Cypher Injection via Unsanitized node_labels — CVE-2026-32247
CVE-2026-32247 (GHSA, getzep/graphiti) web Patched
CVE-2026-32247webHIGH 8.1Patched2026-07-05adx-mcp-server KQL Injection via table_name Parameter (CVE-2026-33980)
CVE-2026-33980 web Patched
CVE-2026-33980webHIGH 8.8Patched2026-07-05Flowise Custom MCP Environment Variable Case Bypass
None assigned as of 2026-07-03 web Unverified
None assigned as of 2026-07-03webHIGHUnverified2026-07-03Authenticated Command Injection in LiteLLM MCP Test Endpoints (CVE-2026-42271) KEV EPSS 84%
CVE-2026-42271 web Patched
CVE-2026-42271webHIGH 8.7Patched2026-07-01