PoC Archive PoC Archive

tag

Nginx

Nginx HTTP/3 QUIC Pool Corruption RCE (CVE-2026-42530)
CVE-2026-42530 binary Unverified
CVE-2026-42530binaryHIGH 8.1Unverified2026-09-03UniFi OS -- Unauthenticated Command Injection RCE (CVE-2026-34910) KEV EPSS 87%
CVE-2026-34910, CVE-2026-34909, CVE-2026-34908 network Patched
CVE-2026-34910, CVE-2026-34909, CVE-2026-34908networkCRITICAL 10Patched2026-08-16nginx PCRE Capture Variable Heap Overflow to Pre-Auth RCE (CVE-2026-42533)
CVE-2026-42533 web Patched
CVE-2026-42533webCRITICAL 9.8Patched2026-08-16IngressNightmare: Kubernetes ingress-nginx Admission Controller Shared-Library Injection RCE (CVE-2025-1974) EPSS 100%
CVE-2025-1974 cloud Unverified
CVE-2025-1974cloudCRITICAL 9.8Unverified2026-07-06nginx Resolver Use-After-Free in OCSP Stapling (CVE-2026-40701)
CVE-2026-40701 web Patched
CVE-2026-40701webMEDIUM 6.3Patched2026-07-05Nginx QUIC/HTTP-3 DCID Length Heap Overflow Lab (CVE-2026-0211)
CVE-2026-0211 (repository explicitly labels this as a hypothetical/simulated CVE for coursework, not a confirmed vendor-assigned vulnerability) web Unverified
CVE-2026-0211webHIGHUnverified2026-07-05nginx PoolSlip × Rift Chained ASLR-Independent Remote Code Execution (CVE-2026-9256 / CVE-2026-42945)
CVE-2026-9256 ("PoolSlip"), chained with CVE-2026-42945 ("rift") web Unverified
CVE-2026-9256webCRITICALUnverified2026-07-05NGINX HTTP/2 Frame Injection via Vulnerable Upstream Proxying (CVE-2026-42926)
CVE-2026-42926 web Patched
CVE-2026-42926webHIGHPatched2026-07-05HPE Aruba AOS-CX Pre-Auth REST API Bypass via nginx Version Smuggling (CVE-2026-23813)
CVE-2026-23813 network Patched
CVE-2026-23813networkCRITICAL 9.8Patched2026-07-05NGINX Rift — Heap Buffer Overflow RCE (CVE-2026-42945) EPSS 68%
CVE-2026-42945 web Unverified
CVE-2026-42945webCRITICAL 9.8Unverified2026-05-14